Sceawere

Vulnerability Detail

CVE-2026-94538UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP File Download Authorization Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
JoomUnited
Product
WP File Download
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary files.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-10T07:16:42.070Z",
  "pubdate": "2026-10-10T07:16:42.070Z",
  "executiveSummary": "The WP File Download plugin for WordPress, in all versions up to and including 6.3.9, contains a critical authorization bypass vulnerability.\nThis flaw originates from improper implementation of access control checks, failing to validate user permissions before executing sensitive file management operations.\nThe vulnerability allows authenticated attackers with minimal privileges, such as the Subscriber role, to perform unauthorized administrative actions on files managed by the plugin.\nPotential impacts include the permanent deletion of files, the removal of all items within the trash, unauthorized relocation of files between categories, and the modification of file visibility states (publish/unpublish).\nGiven that this vulnerability requires only a low-privileged account, it poses a significant risk to data integrity and availability within the WordPress environment.\nExploitation is straightforward as the system fails to enforce capability checks during the request handling process for plugin-specific file management functions.",
  "technicalDetails": "The vulnerability is classified as an Improper Authorization flaw, stemming from the plugin's failure to perform adequate nonce validation and capability checks (e.g., current_user_can()) when processing administrative AJAX requests.\nThe WP File Download plugin handles file manipulation tasks via designated handlers that assume the caller is authorized. By failing to verify if the requesting user possesses the necessary privileges, the plugin allows any authenticated WordPress user to trigger these sensitive functions.\nThe attack flow begins when an attacker, authenticated as a subscriber, intercepts or crafts a request targeting the plugin's file management endpoints. Because the backend code lacks restrictive checks, the application processes the request as if it originated from an authorized administrator.\nSpecifically, the vulnerability enables the following unauthorized operations: 1) Permanent deletion of any file, 2) Purging the system trash, 3) Moving files between organizational categories, and 4) Toggling the status of arbitrary files (publish/unpublish).\nThe root cause is the reliance on client-side or implicit trust rather than rigorous server-side verification of user capabilities before executing database or file system modifications. When a request is submitted, the server-side code executes the logic required for the action without checking the 'manage_options' or equivalent capabilities of the session owner.\nAttackers can leverage this by sending standard HTTP POST requests containing the parameters required by the plugin's internal functions. Since the application does not strictly validate the 'user_id' or associated capabilities against the requested action, the plugin proceeds to execute the requested command directly against the database entries and file objects managed by WP File Download.\nThe impact is significant, as it permits unauthorized users to disrupt site content, potentially causing denial-of-service conditions by deleting critical assets, or manipulating sensitive files to influence site front-end presentation. This bypass affects the core file management utility of the plugin, extending to both files uploaded by other users and global configuration files managed via the plugin's interface."
}
CVE-2026-94538: WP File Download Authorization Bypass (HIGH Severity, CVSS: 8.1) | Sceawere