Retour à la veille

CVE-2026-92995

Publié : 27 septembre 2026
Modifié : 27 septembre 2026
Lien officiel NVD

Description détaillée

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

Références et Patchs