PatchSiren

CodePeople2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CodePeople2 CVE published 2026-10-10

CVE-2026-94590

CVE-2026-94590 is an Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads that allows Exploitation of Trusted Credentials. This issue affects Sell Downloads: from n/a through 1.2.3. Defenders responsible for WordPress installations using the Sell Downloads plugin, especially those using version 1.2.3 or earlier, should assess exposure and pr [truncated]