CVE-2026-97332

CVE-2026-97332 published: The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticat...

View full NVD advisory → ← Back to CVE watch