CVE-2026-92995
Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
| Vendor | unknown |
| Product | verge3d publishing and e-commerce |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown verge3d publishing and e-commerce
Be the first to know when new unknown vulnerabilities affecting unknown verge3d publishing and e-commerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Verge3D Publishing and E-Commerce
0 โค 4.13.0
References
Credits
Raphael P. Cigana WPScan