Sceawere

Vulnerability Detail

CVE-2026-94590UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sell Downloads Improper Communication Verification

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
CodePeople2
Product
Sell Downloads
Attack Type
Improper Verification of Source of a Communication Channel
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-10T19:16:58.917Z",
  "pubdate": "2026-10-10T19:16:58.917Z",
  "executiveSummary": "The Sell Downloads plugin for WordPress is susceptible to an Improper Verification of Source of a Communication Channel vulnerability, classified under CWE-807.\nThis vulnerability exists within versions n/a through 1.2.3 of the plugin.\nThe flaw allows for the exploitation of trusted credentials, meaning an attacker can manipulate or spoof communication channels that the application relies upon to verify the integrity or source of requests.\nBy bypassing source verification mechanisms, a remote attacker can potentially perform unauthorized actions that the system assumes to be trusted.\nThe risk is significant as it undermines the trust model of the plugin's communication flows, potentially allowing for account takeover, unauthorized data access, or the manipulation of transaction-related credentials.\nExploitation does not necessarily require high-level administrative privileges, provided the attacker can intercept or inject traffic into the communication channel being verified.\nUsers of the affected versions are at risk of security compromise due to the plugin's failure to properly validate the origin of requests.",
  "technicalDetails": "The vulnerability, identified as Improper Verification of Source of a Communication Channel (CWE-807), stems from the plugin's failure to adequately authenticate or validate the source of critical communication requests.\nIn the context of the Sell Downloads plugin, this implies that the application relies on information provided in communication packets—such as headers, parameters, or source IP addresses—to make security-critical decisions without performing sufficient cryptographic verification or sanity checks to ensure the data originated from a trusted entity.\nThe root cause is a failure in the trust boundary implementation, where the system implicitly trusts the communication channel, assuming that the received data is authentic and originated from a legitimate source.\nAttack flow typically involves an attacker positioning themselves in a position to influence the communication channel. Because the plugin does not verify the actual source, an attacker can craft malicious requests that appear legitimate to the plugin's internal logic.\nWhen the plugin processes these requests, it fails to challenge the authenticity of the sender, allowing the request to be treated as a trusted communication.\nThis leads to the exploitation of trusted credentials, where the attacker can effectively masquerade as an authorized entity, user, or service.\nFor example, if the communication channel is used to confirm download permissions or validate transaction status, an attacker could inject fraudulent data that the application accepts as valid, potentially granting unauthorized access to downloadable files or manipulating internal credential stores.\nThe vulnerable component is the mechanism responsible for handling external communication within the plugin's source code, specifically where input verification is omitted or incorrectly implemented for incoming requests.\nBecause the system validates the channel instead of the content or the originator, the security architecture is inherently flawed, allowing a bypass of intended access controls.\nThe post-exploitation impact includes the potential for unauthorized data exfiltration, the compromising of user download authorizations, and the general breakdown of the plugin’s security controls related to user identity and transaction processing.\nThis vulnerability is particularly critical for plugins managing downloadable assets, as it directly impacts the authorization mechanism used to secure proprietary content."
}
CVE-2026-94590: Sell Downloads Improper Communication Verification (MEDIUM Severity, CVSS: 6.5) | Sceawere