CVE-2026-97332

NONE
Updated Oct 04, 2026
Unknown
Parameter Value
Affected Versions before 2.2.0
Type CWE-284 Improper Access Control
Vendor Unknown
Public PoC No

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.

Vulnerable Products

unknown:user private files