Impact
The Verge3D Publishing and E-Commerce WordPress plugin allows unauthenticated users to download the digital‑goods files linked to any order via its v3d_download_file handler. This exposes users’ purchased products to anyone who can discover or guess an order identifier, resulting in a confidentiality breach of proprietary digital goods and potential economic loss.
Affected Systems
WordPress installations running the Verge3D Publishing and E-Commerce plugin version 4.13.0 or earlier are affected. Any site that has not updated the plugin beyond this version is vulnerable.
Risk and Exploitability
The flaw requires no credentials; an attacker can request the download endpoint with a valid or guessed order ID over HTTP. Because the endpoint is publicly reachable, exploitation can be performed remotely from any network. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Without a CVSS score, the precise severity cannot be quantified, but the lack of access control presents a high risk of unauthorized data disclosure.
OpenCVE Enrichment