CVE-2026-97332 - User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)
CVE ID :CVE-2026-97332
Published : Oct. 4, 2026, 6 a.m. | 1 hour, 13 minutes ago
Description :The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 4, 2026, 6 a.m. | 1 hour, 13 minutes ago
Description :The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...