PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94538 JoomUnited CVE debrief

The WP File Download plugin for WordPress has a vulnerability that allows authenticated attackers with subscriber-level access to delete or modify arbitrary files. This issue arises from a missing authorization check, which could lead to potential data loss or corruption, increased risk of website compromise or defacement, and disruption to website functionality or availability. The vulnerability affects all versions up to, and including, 6.3.9 of the WP File Download plugin. To address this issue, it is crucial for WordPress administrators and users with subscriber-level access or above who use the WP File Download plugin to take immediate action.

Vendor
JoomUnited
Product
WP File Download
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress administrators and users with subscriber-level access or above who use the WP File Download plugin should be aware of this vulnerability and take immediate action to address it. The vulnerability poses a risk to website integrity and data security, potentially leading to data loss or corruption, increased risk of website compromise or defacement, and disruption to website functionality or availability.

Why it matters

The WP File Download plugin vulnerability allows authenticated attackers to delete or modify arbitrary files, posing a risk to website integrity and data security.

  • Potential data loss or corruption due to unauthorized file deletion or modification
  • Increased risk of website compromise or defacement
  • Potential disruption to website functionality or availability

Technical summary

The WP File Download plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with subscriber-level access to delete or modify arbitrary files. This issue arises from a missing authorization check in the plugin's handling of the 'task' parameter to multiple functions. The vulnerability affects all versions up to, and including, 6.3.9 of the WP File Download plugin. To address this issue, it is crucial for WordPress administrators and users with subscriber-level access or above who use the WP File Download plugin to take immediate action.

Defensive priority

High

Recommended defensive actions

  • Review and update WP File Download plugin versions to ensure authorization checks are in place
  • Monitor for suspicious file deletion or modification activity
  • Restrict access to sensitive files and directories
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or affected versions. The WP File Download plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with subscriber-level access to delete or modify arbitrary files. There is no evidence of public exploitation, but defenders should verify the presence of affected product deployments in managed environments and review official advisories for validation of affected scope, severity,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94538 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94538

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94538 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94538

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.