Verge3D Publishing and E-Commerce, CVE-2026-92995
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 27, 2026
- Research Description
- The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
- Affected versions
-
max 4.13.1.
- Status
-
vulnerable