CVE-2026-97267: WordPress Prevent files / folders access plugin <= 2.6.7 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
Affected Software
1 affected component
WordPress Prevent files / folders access<=2.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Prevent files / folders access pluginto a version that resolves this vulnerability.Fixed in 2.6.8
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be treated as affected?
WordPress sites using Prevent files / folders access version 2.6.7 or earlier should be treated as affected based on the available information.
2
What access does an attacker need to exploit this issue?
The vulnerability is network-reachable and has low attack complexity, but requires low-level privileges. The description specifically identifies Subscriber-level access.
3
What is the expected security impact?
The reported impact is limited to low confidentiality impact. No integrity or availability impact is indicated, and user interaction is not required.