Authorization Bypass Vulnerability in WP File Download by WordPress
CVE-2026-94538
8.1HIGH
What is CVE-2026-94538?
The WP File Download plugin for WordPress is susceptible to an authorization bypass flaw affecting all versions up to 6.3.9. This vulnerability arises from inadequate verification of user permissions, allowing authenticated attackers with subscriber-level access or higher to execute unauthorized actions. These actions include the ability to permanently delete any file managed by the plugin, empty the entire trash, transfer files between categories, and publish or unpublish arbitrary files. Such weaknesses pose significant risks to WordPress site security, making it essential for site administrators to apply necessary patches and ensure their plugin is up to date.
Affected Version(s)
WP File Download 0 <= 6.3.9