🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: WordPress

Mô tả

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

Chi tiết

Trạng tháiDeferred
Điểm CVSS5.3 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ngày công bố13:17 27/09/2026
Ngày cập nhật23:38 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-200

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
23:47 28/09/2026 CREATED cve MEDIUM

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).