The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
CVE-2026-97332
NONE
Updated Oct 04, 2026
Unknown
unknown:user private files
CVE Details
CVE ID
CVE-2026-97332
Published Date
Oct 04, 2026
Vendor
Unknown
Severity
NONE
Impact
Minimal impact
Source
View Advisory