CVE-2026-28569: WordPress SSL Zen plugin <= 4.7.43 - Reflected Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SSL Zen pluginto a version that resolves this vulnerability.Fixed in 4.7.43 - Upgrade
Upgrade
SSL Zento a version that resolves this vulnerability.Fixed in 4.7.43
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability can be exploited without authentication over the network, but it requires a victim to interact with attacker-controlled content, such as following a crafted link or loading a malicious page.
Which installations are affected?
SSL Zen versions 4.7.43 and earlier are affected. The supplied information does not state whether the vulnerable behavior is enabled or reachable in the plugin's default configuration.
What is the likely impact if exploitation succeeds?
Successful exploitation can expose, alter, or disrupt data and functionality within the affected security scope, with low impact to confidentiality, integrity, and availability. Because this is reflected XSS, impact depends on the context of the user who triggers the malicious request.