CVE-2026-97332
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 04, 2026
Vendor
unknown
Description
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.