Directory Traversal Vulnerability in WP File Download Plugin by WordPress
CVE-2026-14975

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2026

What is CVE-2026-14975?

The WP File Download plugin for WordPress is susceptible to a directory traversal issue, affecting all versions up to and including 6.3.8. This vulnerability enables authenticated attackers, including those with just subscriber access, to gain unauthorized access to the contents of arbitrary files on the server. By manipulating the '_wpfd_file_metadata['file']' post-meta value through an unsecured file saving handler, attackers can exploit the unguarded streaming endpoint to resolve and expose sensitive file paths. This flaw potentially allows attackers to read confidential data, posing a significant risk to server security.

Affected Version(s)

WP File Download 0 <= 6.3.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3
.