Description
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
Published: 2026-10-04
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated Private File Disclosure
Action: Immediate Patch
AI Analysis

Impact

The User Private Files plugin for WordPress versions prior to 2.2.0 allows an unauthenticated user to download private files of other users on multisite installations. The vulnerability occurs because the rewrite rule that sends file requests through the plugin’s access check is never triggered. Consequently, any user can construct a URL to the private file location and retrieve its contents directly, exposing sensitive user data. The weakness is a clear example of improper access control that can lead to information disclosure.

Affected Systems

Any WordPress site that has the User Private Files plugin installed with a version earlier than 2.2.0 and is configured as a multisite network is at risk. The vulnerability does not affect single-site installations because the rewrite rule remains in place. Site owners should verify the plugin version and the multisite configuration. If the plugin is updated to 2.2.0 or later, the bypass is fixed; earlier versions remain vulnerable.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in CISA KEV, so public exploitation statistics are unknown. Nonetheless, the CVSS score is not provided, but the nature of the flaw—unauthenticated access to any private file—suggests a high impact on confidentiality and potentially integrity if the files contain executable code. Attackers can simply browse the network’s private file URLs; no special privileges are required. As a result, the risk remains significant until the plugin is upgraded or an equivalent mitigation is applied.

Generated by OpenCVE AI on October 4, 2026 at 07:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the User Private Files plugin to version 2.2.0 or later.
  • If an upgrade is not immediately possible, disable multisite mode or restrict plugin use to single-site installations to prevent the rewrite rule bypass.
  • Add server‑level rules to block direct access to private file directories, for example by updating the .htaccess file to deny all requests to the private files folder except through the plugin's authorized entry point.
  • Verify that no residual private files are accessible by performing a file‑list scan and restrict permissions on the file system.

Generated by OpenCVE AI on October 4, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
Title User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-04T06:00:24.076Z

Reserved: 2026-09-24T11:58:42.116Z

Link: CVE-2026-97332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:34.303

Modified: 2026-10-04T07:16:34.303

Link: CVE-2026-97332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T07:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control