CVE-2026-94590: WordPress Sell Downloads plugin <= 1.2.3 - Broken Access Control vulnerability
Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Sell Downloads pluginto a version that resolves this vulnerability.Fixed in 1.2.4
Event History
Frequently Asked Questions
Which installations are affected?
CodePeople2 Sell Downloads installations are affected through version 1.2.3. The available data does not identify a fixed version.
What does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low attack complexity, and does not require privileges or user interaction. The issue involves improper verification of a communication channel and exploitation of trusted credentials.
What is the expected impact?
The reported severity is medium, with a CVSS score of 6.5. The vector indicates low confidentiality and integrity impact, with no availability impact.