CVE-2026-94538 - WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion/Modification via 'task' Parameter to Multiple Functions
CVE ID :CVE-2026-94538 Published : Oct. 10, 2026, 6:40 a.m. | 49 minutes ago Description :The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to...