{"id":"CVE-2026-92995","published":"2026-09-27T06:17:22.600","lastModified":"2026-09-28T16:38:58.950","description":"The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/184e6a19-92d4-48f6-8e54-2511e0f3f316/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}