PatchSiren cyber security CVE debrief
CVE-2026-97332 User Private Files CVE debrief
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations. This allows unauthenticated users to retrieve other users' private files directly due to a flawed rewrite rule that fails to route file requests through its access check. The vulnerability impacts WordPress multisite installations with the plugin installed, potentially leading to unauthorized access to sensitive user data. Defenders should assess their exposure and prioritize updating to version 2.2.0 or later.
- Vendor
- User Private Files
- Product
- User Private Files WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders managing WordPress multisite installations with the User Private Files plugin should assess exposure and prioritize updating to version 2.2.0 or later. This includes IT administrators, security teams, and operators responsible for maintaining WordPress installations. They should verify the presence of this vulnerability in their environments, monitor for potential exploitation attempts, and implement compensating controls if necessary.
Why it matters
CVE-2026-97332 allows unauthenticated users to access private files on WordPress multisite installations with the User Private Files plugin before version 2.2.0. Defenders should verify exposure, prioritize updates, and monitor for exploitation attempts.
- Potential unauthorized access to sensitive user data.
- Possible data breaches or leakage of private files.
- Need for verification of plugin version and multisite installation configuration.
- Potential impact on user trust and reputation.
Technical summary
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, allowing unauthenticated users to retrieve other users' private files directly due to a flawed rewrite rule. This vulnerability impacts WordPress multisite installations with the plugin installed, potentially leading to unauthorized access to sensitive user data. The vulnerability class is related to improper access control and file protection mechanisms. Defenders should prioritize verifying the presence of this vulnerability in their WordPress multisite installations and ensure the plugin is updated to version 2.2.0 or later.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress multisite installations and ensure the plugin is updated to version 2.2.0 or later.
Recommended defensive actions
- Verify the presence of the User Private Files WordPress plugin version 2.2.0 or later in your multisite installations.
- Restrict access to private files through alternative means, such as file permissions or access controls.
- Monitor for potential exploitation attempts targeting this vulnerability.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE description and source reference indicate that the plugin's flawed rewrite rule allows unauthenticated access to private files on multisite installations. The vulnerability was reported by WPScan and documented in their vulnerability database. There are no known exploit details publicly available, but defenders should verify the presence of this vulnerability in their WordPress multisite installations. The CVE record was published on 2026-10-04T07:16:34.303Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97332 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97332
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97332 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97332
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/d6a144b3-84e3-43eb-92d3-fd4505dd0e1c/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.