<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:joomunited:wp_file_download:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ajoomunitedwp_file_downloadwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ajoomunitedwp_file_downloadwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in WP File Download Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wp-file-download-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 07:52:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wp-file-download-auth-bypass/</guid><description>An authorization bypass vulnerability in WP File Download allows authenticated users with subscriber-level access to delete or manipulate managed files.</description><content:encoded><![CDATA[<p>The WP File Download plugin for WordPress, in all versions up to and including 6.3.9, contains an authorization bypass vulnerability identified as CVE-2026-94538. The flaw stems from insufficient access control checks within the plugin, which fails to verify that the requesting user has the necessary privileges before executing sensitive management tasks.</p>
<p>This vulnerability allows any authenticated user, including those with restricted 'subscriber' roles, to bypass intended authorization checks. Consequently, an attacker can perform administrative actions such as permanently deleting managed files, clearing the file trash, reorganizing file categories, and modifying the publication status of sensitive documents. This poses a significant risk to site integrity and data confidentiality, as unauthorized actors can disrupt file management operations or delete critical assets without administrative authorization. Organizations utilizing this plugin should prioritize updating to a patched version once released by JoomUnited.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized users to perform destructive actions against the plugin's file system, leading to data loss, service disruption, and the potential unauthorized exposure of restricted files if their publication status is manipulated.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all WordPress instances running the WP File Download plugin.</li>
<li>Update the WP File Download plugin to version 6.4.0 or the latest available patched version provided by JoomUnited.</li>
<li>Restrict subscriber-level account creation and monitor user activity logs for suspicious administrative actions within the plugin's file management interface.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>web-application</category></item></channel></rss>