VYPR

Verge3D Publishing and E-Commerce

by WordPress

CVEs (2)

  • CVE-2026-92994HigSep 30, 2026
    risk 0.57cvss 8.8epss 0.00

    The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing…

  • CVE-2026-92995MedSep 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.