Skip to content
Threat Feed
high advisory

Authorization Bypass in WP File Download Plugin

An authorization bypass vulnerability in WP File Download allows authenticated users with subscriber-level access to delete or manipulate managed files.

CVE search metadata

CVE search record: CVE-2026-94538. Severity: high. CVSS: 8.1. KEV: no. Product: WP File Download (<= 6.3.9). Brief: Authorization Bypass in WP File Download Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wp-file-download-auth-bypass/

The WP File Download plugin for WordPress, in all versions up to and including 6.3.9, contains an authorization bypass vulnerability identified as CVE-2026-94538. The flaw stems from insufficient access control checks within the plugin, which fails to verify that the requesting user has the necessary privileges before executing sensitive management tasks.

This vulnerability allows any authenticated user, including those with restricted 'subscriber' roles, to bypass intended authorization checks. Consequently, an attacker can perform administrative actions such as permanently deleting managed files, clearing the file trash, reorganizing file categories, and modifying the publication status of sensitive documents. This poses a significant risk to site integrity and data confidentiality, as unauthorized actors can disrupt file management operations or delete critical assets without administrative authorization. Organizations utilizing this plugin should prioritize updating to a patched version once released by JoomUnited.

Impact

Successful exploitation allows unauthorized users to perform destructive actions against the plugin's file system, leading to data loss, service disruption, and the potential unauthorized exposure of restricted files if their publication status is manipulated.

Recommendation

  • Identify all WordPress instances running the WP File Download plugin.
  • Update the WP File Download plugin to version 6.4.0 or the latest available patched version provided by JoomUnited.
  • Restrict subscriber-level account creation and monitor user activity logs for suspicious administrative actions within the plugin's file management interface.

Mitigations

Upgrade WP File Download to version 6.4.0 or later

immediate IT Operations

CVE-2026-94538