Impact
The User Private Files plugin for WordPress versions prior to 2.2.0 allows an unauthenticated user to download private files of other users on multisite installations. The vulnerability occurs because the rewrite rule that sends file requests through the plugin’s access check is never triggered. Consequently, any user can construct a URL to the private file location and retrieve its contents directly, exposing sensitive user data. The weakness is a clear example of improper access control that can lead to information disclosure.
Affected Systems
Any WordPress site that has the User Private Files plugin installed with a version earlier than 2.2.0 and is configured as a multisite network is at risk. The vulnerability does not affect single-site installations because the rewrite rule remains in place. Site owners should verify the plugin version and the multisite configuration. If the plugin is updated to 2.2.0 or later, the bypass is fixed; earlier versions remain vulnerable.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA KEV, so public exploitation statistics are unknown. Nonetheless, the CVSS score is not provided, but the nature of the flaw—unauthenticated access to any private file—suggests a high impact on confidentiality and potentially integrity if the files contain executable code. Attackers can simply browse the network’s private file URLs; no special privileges are required. As a result, the risk remains significant until the plugin is upgraded or an equivalent mitigation is applied.
OpenCVE Enrichment