Loading market data...
← Back to CVE feed

CVE-2026-92995

MEDIUM CVSS 5.3 View on NVD ↗

Description

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 27, 2026 06:17 UTC Modified: Sep 28, 2026 02:17 UTC