Improper Verification Vulnerability in CodePeople2 Sell Downloads by CodePeople
CVE-2026-94590

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-94590?

A vulnerability in the CodePeople2 Sell Downloads plugin allows for improper verification of the source of a communication channel, which can lead to the exploitation of trusted credentials. This flaw enables unauthorized users to potentially bypass security measures and access sensitive information or functionalities. The issue exists in versions of Sell Downloads prior to 1.2.3.

Affected Version(s)

Sell Downloads 0 <= 1.2.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

c4st1e | Patchstack Bug Bounty Program
.