Broken Access Control in Prevent Files/Folders Access Plugin by WordPress
CVE-2026-97267
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-97267?
The Prevent Files/Folders Access Plugin for WordPress versions up to 2.6.7 is susceptible to broken access control vulnerabilities. This flaw may allow unauthorized users to gain access to restricted files and folders, posing significant risks to sensitive information. Proper access controls must be enforced to mitigate these vulnerabilities and protect the integrity of user data.
Affected Version(s)
Prevent files / folders access <= 2.6.7