CVE-2026-92995: Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated user can exploit the exposed download handler. The issue affects digital-goods files attached to orders.
What access or information does an attacker need?
The available information states that no authentication is required. It does not specify whether an attacker needs an order identifier, file identifier, or other request details.
Are customer download files exposed without a valid purchase authorization?
Yes. The handler can allow unauthenticated users to download digital-goods files attached to any order without authorization.
Which plugin versions are known to be affected?
The issue is reported in the Verge3D Publishing and E-Commerce WordPress plugin through version 4.13.0.