Skip to main content
Vulnerability Database/CVE-2026-97331

CVE-2026-97331: WordPress User Private Files Plugin Flaw

CVE-2026-97331 is an information disclosure flaw in the User Private Files WordPress plugin that lets authenticated users access email addresses of any registered account. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-97331 Overview

CVE-2026-97331 affects the User Private Files WordPress plugin in versions prior to 2.1.9. The plugin fails to validate that a supplied user belongs to the document being operated on before returning that user's email address. Any authenticated user, including a Subscriber-level account, can harvest email addresses of other registered accounts, including administrators. The flaw is categorized as information exposure [CWE-200] and requires low privileges to exploit over the network.

Critical Impact

Low-privileged attackers can enumerate email addresses of all registered WordPress accounts, including administrators, enabling targeted phishing and credential-stuffing campaigns.

Affected Products

  • User Private Files WordPress plugin versions before 2.1.9
  • WordPress sites with Subscriber-level or higher account registration enabled
  • Any WordPress installation exposing the vulnerable document endpoint to authenticated users

Discovery Timeline

  • 2026-10-07 - CVE-2026-97331 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-97331

Vulnerability Analysis

The User Private Files plugin provides document-sharing functionality tied to specific WordPress users. When processing a request that references a user identifier alongside a document identifier, the plugin returns the associated user's email address. The plugin does not verify that the supplied user is actually associated with the referenced document.

An authenticated attacker can iterate through user IDs and receive the corresponding email address for each account. Because WordPress user IDs are sequential integers, enumeration is straightforward. Administrator accounts, which typically occupy low numeric IDs, are exposed by this flaw.

The disclosed email addresses enable targeted phishing, password-reset abuse, and credential-stuffing attacks against privileged users. See the WPScan Vulnerability Report for additional technical context.

Root Cause

The root cause is a missing authorization check [CWE-200]. The plugin trusts the user identifier supplied in the request and returns associated personal data without confirming the requesting account has a legitimate relationship to that user or document. This is a broken access control pattern known as an insecure direct object reference.

Attack Vector

Exploitation requires an authenticated session, which can be obtained on any WordPress site that permits open user registration. The attacker issues requests to the vulnerable endpoint, varying the user ID parameter, and parses the returned email addresses. No user interaction, no elevated privileges, and no social engineering are required.

No verified proof-of-concept code is available in the reference material. Refer to the WPScan advisory for exploitation specifics.

Detection Methods for CVE-2026-97331

Indicators of Compromise

  • Repeated authenticated requests to User Private Files plugin endpoints from a single session, each varying a user ID parameter
  • Subscriber or low-privilege accounts generating high volumes of document-related API calls
  • Newly registered accounts issuing enumeration patterns against sequential user IDs shortly after sign-up

Detection Strategies

  • Review WordPress access logs for sequential or scripted access to User Private Files endpoints
  • Correlate low-privilege account activity with retrieval of data belonging to unrelated users
  • Alert on authenticated accounts receiving response payloads containing email addresses outside their own profile scope

Monitoring Recommendations

  • Enable verbose logging on the WordPress REST API and admin-ajax endpoints used by the plugin
  • Track account creation rates and subsequent API activity to identify disposable enumeration accounts
  • Monitor outbound email delivery for spikes in phishing attempts targeting administrator addresses

How to Mitigate CVE-2026-97331

Immediate Actions Required

  • Update the User Private Files plugin to version 2.1.9 or later on all WordPress installations
  • Audit existing Subscriber accounts and remove any created by unknown or suspicious sources
  • Rotate administrator email addresses if phishing or targeted outreach is observed following disclosure

Patch Information

The vendor addressed the issue in User Private Files version 2.1.9. The patch adds validation ensuring that the supplied user is associated with the document being operated on before returning the user's email address. Administrators should verify the installed version through the WordPress plugin management console.

Workarounds

  • Disable the User Private Files plugin until the patch can be applied
  • Restrict new user registration on affected WordPress sites to reduce the pool of accounts that can authenticate
  • Place the plugin's endpoints behind a web application firewall rule that limits request rates per authenticated session
bash
# Verify installed plugin version via WP-CLI
wp plugin get user-private-files --field=version

# Update to the patched release
wp plugin update user-private-files --version=2.1.9

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.