Description
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Email Address Disclosure
Action: Apply Patch
AI Analysis

Impact

The User Private Files WordPress plugin prior to version 2.1.9 allows an attacker who is logged in, such as a Subscriber, to call the dpk_upvf_rmv_access function without first validating that the requested document belongs to the user. This omission causes the plugin to return the email address of any registered account, exposing sensitive personal information. The weakness is an access control flaw (CWE‑284) that results in unintended information disclosure.

Affected Systems

WordPress sites that have the User Private Files plugin installed with a version earlier than 2.1.9 are vulnerable. Any authenticated user with sufficient privileges can trigger the flaw, regardless of role, and obtain email addresses of all registered accounts, including administrators.

Risk and Exploitability

Exploitation requires only–a valid WordPress login and knowledge of the vulnerable endpoint URL. Because no additional authentication or token checks are performed, an attacker can obtain sensitive email addresses with minimal effort. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the straightforward attack path and the visibility of user data make the risk significant for unpatched sites.

Generated by OpenCVE AI on October 7, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the User Private Files plugin to version 2.1.9 or later, which removes the access control bug.
  • Restrict or disable the dpk_upvf_rmv_access endpoint for all but highly privileged users by configuring your web server or a firewall to block requests to that action from lower‑privileged roles.
  • If the plugin offers a configuration option, adjust settings to hide or disable email address retrieval features. If no such option exists, consider disabling the plugin entirely or removing the feature manually through code changes.

Generated by OpenCVE AI on October 7, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
Title User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:08.993Z

Reserved: 2026-09-24T11:58:38.220Z

Link: CVE-2026-97331

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:02.773

Modified: 2026-10-07T07:17:02.773

Link: CVE-2026-97331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T07:45:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control