Sceawere

Vulnerability Detail

CVE-2026-92995UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Verge3D Plugin Unauthenticated File Download

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Unknown
Product
Verge3D Publishing and E-Commerce
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-27T06:17:22.600Z",
  "pubdate": "2026-09-27T06:17:22.600Z",
  "executiveSummary": "The Verge3D Publishing and E-Commerce WordPress plugin, versions up to and including 4.13.0, contains an insecure direct object reference (IDOR) or broken access control vulnerability within its file-download handler.\nThis vulnerability allows unauthenticated, remote attackers to download digital goods and files associated with any customer order without requiring purchase authentication or administrative privileges.\nThe lack of server-side authorization checks on the download handler exposes sensitive intellectual property and proprietary digital assets to unauthorized public access.\nThe risk implication is critical, as it bypasses the intended e-commerce monetization and access control mechanisms, potentially leading to unauthorized data exfiltration.\nNo specific user interaction is required for exploitation; the vulnerability is accessible to any remote attacker who can reach the WordPress instance and identify the download request structure.\nThis represents a failure in the plugin's access control architecture, permitting unrestricted retrieval of sensitive attachments.",
  "technicalDetails": "The vulnerability originates from an improperly secured file-download handler within the Verge3D Publishing and E-Commerce plugin. The plugin fails to validate the session state or authorization status of the requester before processing file retrieval requests.\nThe root cause is a deficiency in the access control layer where the application relies on client-side requests without verifying if the requesting user possesses the necessary privileges or has successfully completed an associated purchase transaction to access the requested resource.\nExploitation is straightforward and does not require authentication. An attacker can identify the endpoint responsible for handling digital downloads. By manipulating the request parameters—typically via URL parameters—that identify specific files or order IDs, an attacker can iterate through or target specific resources.\nThe attack flow proceeds as follows: First, the attacker identifies a target resource identifier (e.g., file ID or order number) associated with digital content managed by the Verge3D plugin. Second, the attacker crafts a malicious HTTP GET request targeting the plugin's download handler endpoint. Third, because the underlying code lacks a conditional check to ensure the user is logged in or authorized for the specific resource, the server proceeds to locate the file in the WordPress upload directory or associated storage path. Finally, the server streams the binary content of the file back to the attacker's browser, effectively bypassing the e-commerce storefront's commercial logic.\nThe vulnerable component is the internal download controller logic, which handles file requests for digital goods. Versions affected include all releases up to and including 4.13.0.\nThe attack is persistent across any network exposure of the WordPress site. Post-exploitation, an attacker can harvest all digital goods hosted by the plugin, compromising intellectual property, software assets, or premium content without payment. There is no requirement for elevated privileges, as the system fails to verify authorization at the application layer."
}
CVE-2026-92995: Verge3D Plugin Unauthenticated File Download (MEDIUM Severity, CVSS: 5.3) | Sceawere