Review
User Private Files
CVE published 2026-10-04
CVE-2026-97332
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations. This allows unauthenticated users to retrieve other users' private files directly due to a flawed rewrite rule that fails to route file requests through its access check. The vulnerability impacts WordPress multisite installations with the plugin installed, potentially leadin [truncated]