PatchSiren

User Private Files CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review User Private Files CVE published 2026-10-04

CVE-2026-97332

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations. This allows unauthenticated users to retrieve other users' private files directly due to a flawed rewrite rule that fails to route file requests through its access check. The vulnerability impacts WordPress multisite installations with the plugin installed, potentially leadin [truncated]