User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)
Summary
| CVE | CVE-2026-97332 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-04 07:16:34 UTC |
| Updated | 2026-10-04 07:16:34 UTC |
| Description | The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly. |
Risk And Classification
Problem Types: CWE-284 Improper Access Control
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | User Private Files | affected 2.2.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/d6a144b3-84e3-43eb-92d3-fd4505dd0e1c | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Akshat Parikh (SN1PER) (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.