Description
The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary files.
Published: 2026-10-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Manipulation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the WordPress plugin allows an attacker who holds a subscriber-level account or higher to delete files, empty the trash, move files between categories, or toggle file publication status. Because the plugin accepts a 'task' parameter without verifying that the current user has the required rights, the only required condition is that the user is authenticated. The result is loss of user data, potential removal of critical content, and exposure to data integrity compromise.

Affected Systems

The issue affects the WordPress plugin "WP File Download" from JoomUnited, versions 6.3.9 and earlier. Sites running any of those releases, regardless of other WordPress configuration, are affected. Only users with the plugin installed are impacted.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, classifying it as high severity. The EPSS score is not available, so the exploitation frequency cannot be quantified, but the lack of an authority check makes the attack trivial for any authenticated user. The vulnerability is not present in the CISA KEV catalog, but it remains a critical concern for sites using the plugin, as an attacker can gain persistence by creating or modifying files. The attack vector is internal; an attacker must already have an account on the WordPress site with subscriber-level or higher privileges. Exploitation requires sending a request to the plugin's endpoints with a crafted 'task' parameter and the target file identifier.

Generated by OpenCVE AI on October 10, 2026 at 08:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP File Download to the latest release that removes the missing authorization checks (v6.4.0 or later).
  • Immediately review the role permissions in WordPress to ensure that subscriber-level users do not have file management capabilities, or use a plugin to revoke those capabilities.
  • If an update cannot be applied immediately, consider temporarily disabling the plugin or removing it from the site until a patched version is installed.

Generated by OpenCVE AI on October 10, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary files.
Title WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion/Modification via 'task' Parameter to Multiple Functions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:12.227Z

Reserved: 2026-09-21T18:29:08.711Z

Link: CVE-2026-94538

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:42.070

Modified: 2026-10-10T07:16:42.070

Link: CVE-2026-94538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:00:03Z

Weaknesses