rootpwn

high · CVSS v3 7.5 · EPSS 0.00136

CVE-2026-97332

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite ins…

Description

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
—
EPSS
0.00136

← All CVEs