Unrated severityNVD Advisory· Published Sep 27, 2026
CVE-2026-92995
CVE-2026-92995
Description
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.13.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.