CVE-2026-97331: User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access
Published Oct 7, 2026
·Updated
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
Affected Software
1 affected component
WordPress User Private Files<2.1.9
Event History
Oct 7, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with the Subscriber role. An attacker does not need administrative privileges.
2
What information can be obtained?
The issue allows disclosure of the email address associated with any registered WordPress account, including administrator accounts.
3
Which plugin versions are affected?
User Private Files versions before 2.1.9 are affected.