GHSA-r5cw-9ppm-v554MediumCVSS 5.3

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to...

Published
September 27, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (1)

📋 Description

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

🔗 References (3)