Sceawere
Vulnerability Detail
CVE-2026-92995UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Verge3D Plugin Unauthenticated File Download
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- Verge3D Publishing and E-Commerce
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-27T06:17:22.600Z",
"pubdate": "2026-09-27T06:17:22.600Z",
"executiveSummary": "The Verge3D Publishing and E-Commerce WordPress plugin, versions up to and including 4.13.0, contains an insecure direct object reference (IDOR) or broken access control vulnerability within its file-download handler.\nThis vulnerability allows unauthenticated, remote attackers to download digital goods and files associated with any customer order without requiring purchase authentication or administrative privileges.\nThe lack of server-side authorization checks on the download handler exposes sensitive intellectual property and proprietary digital assets to unauthorized public access.\nThe risk implication is critical, as it bypasses the intended e-commerce monetization and access control mechanisms, potentially leading to unauthorized data exfiltration.\nNo specific user interaction is required for exploitation; the vulnerability is accessible to any remote attacker who can reach the WordPress instance and identify the download request structure.\nThis represents a failure in the plugin's access control architecture, permitting unrestricted retrieval of sensitive attachments.",
"technicalDetails": "The vulnerability originates from an improperly secured file-download handler within the Verge3D Publishing and E-Commerce plugin. The plugin fails to validate the session state or authorization status of the requester before processing file retrieval requests.\nThe root cause is a deficiency in the access control layer where the application relies on client-side requests without verifying if the requesting user possesses the necessary privileges or has successfully completed an associated purchase transaction to access the requested resource.\nExploitation is straightforward and does not require authentication. An attacker can identify the endpoint responsible for handling digital downloads. By manipulating the request parameters—typically via URL parameters—that identify specific files or order IDs, an attacker can iterate through or target specific resources.\nThe attack flow proceeds as follows: First, the attacker identifies a target resource identifier (e.g., file ID or order number) associated with digital content managed by the Verge3D plugin. Second, the attacker crafts a malicious HTTP GET request targeting the plugin's download handler endpoint. Third, because the underlying code lacks a conditional check to ensure the user is logged in or authorized for the specific resource, the server proceeds to locate the file in the WordPress upload directory or associated storage path. Finally, the server streams the binary content of the file back to the attacker's browser, effectively bypassing the e-commerce storefront's commercial logic.\nThe vulnerable component is the internal download controller logic, which handles file requests for digital goods. Versions affected include all releases up to and including 4.13.0.\nThe attack is persistent across any network exposure of the WordPress site. Post-exploitation, an attacker can harvest all digital goods hosted by the plugin, compromising intellectual property, software assets, or premium content without payment. There is no requirement for elevated privileges, as the system fails to verify authorization at the application layer."
}