User Private Files

WordPress plugin · user-private-files · WordPress.org ↗
0
Critical
0
High
2
Known total
0
Unfixed
Running User Private Files on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 4.3
User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access
CVE.org
>=0, <2.1.9 v2.1.9 CVE-2026-97331 Oct 7, 2026
MEDIUM
CVSS 5.3
User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)
CVE.org
>=0, <2.2.0 v2.2.0 CVE-2026-97332 Oct 4, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.