Ad

CVE-2026-97332

NONE
Обновлено 4 октября 2026
WordPress
Параметр Значение
Уязвимые версии до 2.2.0
Тип уязвимости CWE-284 Improper Access Control
Поставщик WordPress
Публичный эксплойт Нет

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.

Тип уязвимости (CWE)

Уязвимые продукты

unknown:user private files