Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 25 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sslzen
Sslzen ssl Zen Wordpress-extensions Wordpress-extensions ssl Zen |
|
| Vendors & Products |
Sslzen
Sslzen ssl Zen Wordpress-extensions Wordpress-extensions ssl Zen |
Fri, 25 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42. The ssl_zen_messages::getMessages() function builds the 'token_missmatch' message using base64_decode(sanitize_text_field($_REQUEST['uri'])) and (optionally) base64_decode(sanitize_text_field($_REQUEST['host'])). sanitize_text_field() cannot strip HTML/JavaScript that is hidden inside a base64-encoded blob, and the resulting decoded raw HTML is echoed unescaped by showMessage() . This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link. | |
| Title | SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' Parameter | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-25T10:31:39.758Z
Reserved: 2026-07-27T15:29:16.918Z
Link: CVE-2026-17577
Updated: 2026-09-25T10:31:35.638Z
Status : Deferred
Published: 2026-09-25T08:16:40.103
Modified: 2026-09-25T13:08:08.163
Link: CVE-2026-17577
No data.
OpenCVE Enrichment
Updated: 2026-09-25T14:14:31Z