CVE-2026-92995 PUBLISHED

Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file

Assigner: WPScan
Reserved: 17.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

Product Status

Vendor Unknown
Product Verge3D Publishing and E-Commerce
Versions Default: unknown
  • affected from 0 to 4.13.0 (incl.)

Credits

  • Raphael P. Cigana finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE