PatchSiren

Verge3D CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Verge3D CVE published 2026-09-27

CVE-2026-92995

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download digital-goods files attached to any order without authorization. This vulnerability could lead to potential unauthorized access to sensitive digital goods and possible data leakage or exposure of sensitive information. Defenders and administr [truncated]