Sceawere
Vulnerability Detail
CVE-2026-97267UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Prevent Files/Folders Access Broken Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- miniOrange
- Product
- Prevent files / folders access
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T13:17:37.787Z",
"pubdate": "2026-09-30T13:17:37.787Z",
"executiveSummary": "The Prevent files / folders access plugin for WordPress is vulnerable to a broken access control flaw affecting versions 2.6.7 and below.\nThe vulnerability originates from insufficient validation of user privileges, allowing authenticated users with the Subscriber role to bypass access restrictions.\nAn attacker can exploit this flaw to gain unauthorized access to restricted files or folders that should otherwise be protected by the plugin's configuration.\nThis vulnerability is classified as a broken access control issue, which can lead to unauthorized information disclosure of sensitive site data.\nExploitation requires the attacker to possess at least a Subscriber-level account on the target WordPress installation.\nThe risk implication is significant as it undermines the core functionality of the plugin, potentially exposing sensitive administrative, configuration, or private files to unauthorized users.",
"technicalDetails": "The vulnerability exists within the Prevent files / folders access plugin <= 2.6.7, specifically due to improper authorization checks enforced during the file access request handling process.\nRoot cause analysis indicates that the plugin fails to adequately verify the requester's identity or permission level against the security policy defined for restricted resources. While the plugin is designed to restrict access, the implementation of these restrictions does not correctly perform capability checks for the current user session before serving protected content.\nThe attack flow commences with a Subscriber-level user authenticating into the WordPress site. Once authenticated, the attacker crafts a request targeting a protected file or folder path intended to be hidden from standard subscribers. Because the plugin does not properly validate the session's privilege level, the application backend processes the request and serves the protected resource directly to the requester.\nThis bypass occurs because the plugin's access control logic relies on insufficient checks or fails to hook into the WordPress permission system (e.g., current_user_can() checks) effectively. Consequently, the application treats the request as legitimate, allowing the Subscriber to traverse or access files that are restricted via the plugin's configuration interface.\nThe vulnerability is accessible over the network, contingent upon the attacker's ability to maintain a valid Subscriber session. Post-exploitation, an attacker can enumerate and exfiltrate sensitive files, which may include sensitive configuration files, uploaded documents, or other restricted content stored within the WordPress directory structure.\nThis impact extends to potential privilege escalation scenarios or information gathering if the disclosed files contain API keys, database credentials, or personally identifiable information (PII). The vulnerability essentially strips away the intended file-level security, rendering the plugin ineffective at preventing unauthorized access from lower-privileged accounts."
}