Impact
The User Private Files WordPress plugin prior to version 2.1.9 allows an attacker who is logged in, such as a Subscriber, to call the dpk_upvf_rmv_access function without first validating that the requested document belongs to the user. This omission causes the plugin to return the email address of any registered account, exposing sensitive personal information. The weakness is an access control flaw (CWE‑284) that results in unintended information disclosure.
Affected Systems
WordPress sites that have the User Private Files plugin installed with a version earlier than 2.1.9 are vulnerable. Any authenticated user with sufficient privileges can trigger the flaw, regardless of role, and obtain email addresses of all registered accounts, including administrators.
Risk and Exploitability
Exploitation requires only–a valid WordPress login and knowledge of the vulnerable endpoint URL. Because no additional authentication or token checks are performed, an attacker can obtain sensitive email addresses with minimal effort. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the straightforward attack path and the visibility of user data make the risk significant for unpatched sites.
OpenCVE Enrichment