CVE-2026-94538 - WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion/Modification via 'task' Parameter to Multiple Functions
CVE ID :CVE-2026-94538
Published : Oct. 10, 2026, 7:16 a.m. | 30 minutes ago
Description :The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary files.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 10, 2026, 7:16 a.m. | 30 minutes ago
Description :The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary files.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...