CVE-2026-97331
User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
| Vendor | unknown |
| Product | user private files |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user private files
Be the first to know when new unknown vulnerabilities affecting unknown user private files are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Private Files
0 < 2.1.9
References
Credits
Usama Arshad WPScan