{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-file-download--6.3.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:joomunited:wp_file_download:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-94538"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP File Download (\u003c= 6.3.9)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["JoomUnited"],"content_html":"\u003cp\u003eThe WP File Download plugin for WordPress, in all versions up to and including 6.3.9, contains an authorization bypass vulnerability identified as CVE-2026-94538. The flaw stems from insufficient access control checks within the plugin, which fails to verify that the requesting user has the necessary privileges before executing sensitive management tasks.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows any authenticated user, including those with restricted 'subscriber' roles, to bypass intended authorization checks. Consequently, an attacker can perform administrative actions such as permanently deleting managed files, clearing the file trash, reorganizing file categories, and modifying the publication status of sensitive documents. This poses a significant risk to site integrity and data confidentiality, as unauthorized actors can disrupt file management operations or delete critical assets without administrative authorization. Organizations utilizing this plugin should prioritize updating to a patched version once released by JoomUnited.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to perform destructive actions against the plugin's file system, leading to data loss, service disruption, and the potential unauthorized exposure of restricted files if their publication status is manipulated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all WordPress instances running the WP File Download plugin.\u003c/li\u003e\n\u003cli\u003eUpdate the WP File Download plugin to version 6.4.0 or the latest available patched version provided by JoomUnited.\u003c/li\u003e\n\u003cli\u003eRestrict subscriber-level account creation and monitor user activity logs for suspicious administrative actions within the plugin's file management interface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:52:38Z","date_published":"2026-10-10T07:52:38Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wp-file-download-auth-bypass/","summary":"An authorization bypass vulnerability in WP File Download allows authenticated users with subscriber-level access to delete or manipulate managed files.","title":"Authorization Bypass in WP File Download Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wp-file-download-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WP File Download (\u003c= 6.3.9)","version":"https://jsonfeed.org/version/1.1"}