CVE-2026-81275: WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability
Published Sep 10, 2026
·Updated
Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
Affected Software
1 affected component
WordPress Youzify plugin<=1.3.7
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs Subscriber-level privileges. The issue can be exploited remotely and does not require user interaction.
2
What is the impact of successful exploitation?
Successful exploitation can allow arbitrary file download, which may expose confidential information. The available data does not indicate integrity or availability impact.
3
Which versions are affected?
Youzify versions 1.3.7 and earlier are affected.