CVE-2026-97331 Overview
CVE-2026-97331 affects the User Private Files WordPress plugin in versions prior to 2.1.9. The plugin fails to validate that a supplied user belongs to the document being operated on before returning that user's email address. Any authenticated user, including a Subscriber-level account, can harvest email addresses of other registered accounts, including administrators. The flaw is categorized as information exposure [CWE-200] and requires low privileges to exploit over the network.
Critical Impact
Low-privileged attackers can enumerate email addresses of all registered WordPress accounts, including administrators, enabling targeted phishing and credential-stuffing campaigns.
Affected Products
- User Private Files WordPress plugin versions before 2.1.9
- WordPress sites with Subscriber-level or higher account registration enabled
- Any WordPress installation exposing the vulnerable document endpoint to authenticated users
Discovery Timeline
- 2026-10-07 - CVE-2026-97331 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-97331
Vulnerability Analysis
The User Private Files plugin provides document-sharing functionality tied to specific WordPress users. When processing a request that references a user identifier alongside a document identifier, the plugin returns the associated user's email address. The plugin does not verify that the supplied user is actually associated with the referenced document.
An authenticated attacker can iterate through user IDs and receive the corresponding email address for each account. Because WordPress user IDs are sequential integers, enumeration is straightforward. Administrator accounts, which typically occupy low numeric IDs, are exposed by this flaw.
The disclosed email addresses enable targeted phishing, password-reset abuse, and credential-stuffing attacks against privileged users. See the WPScan Vulnerability Report for additional technical context.
Root Cause
The root cause is a missing authorization check [CWE-200]. The plugin trusts the user identifier supplied in the request and returns associated personal data without confirming the requesting account has a legitimate relationship to that user or document. This is a broken access control pattern known as an insecure direct object reference.
Attack Vector
Exploitation requires an authenticated session, which can be obtained on any WordPress site that permits open user registration. The attacker issues requests to the vulnerable endpoint, varying the user ID parameter, and parses the returned email addresses. No user interaction, no elevated privileges, and no social engineering are required.
No verified proof-of-concept code is available in the reference material. Refer to the WPScan advisory for exploitation specifics.
Detection Methods for CVE-2026-97331
Indicators of Compromise
- Repeated authenticated requests to User Private Files plugin endpoints from a single session, each varying a user ID parameter
- Subscriber or low-privilege accounts generating high volumes of document-related API calls
- Newly registered accounts issuing enumeration patterns against sequential user IDs shortly after sign-up
Detection Strategies
- Review WordPress access logs for sequential or scripted access to User Private Files endpoints
- Correlate low-privilege account activity with retrieval of data belonging to unrelated users
- Alert on authenticated accounts receiving response payloads containing email addresses outside their own profile scope
Monitoring Recommendations
- Enable verbose logging on the WordPress REST API and admin-ajax endpoints used by the plugin
- Track account creation rates and subsequent API activity to identify disposable enumeration accounts
- Monitor outbound email delivery for spikes in phishing attempts targeting administrator addresses
How to Mitigate CVE-2026-97331
Immediate Actions Required
- Update the User Private Files plugin to version 2.1.9 or later on all WordPress installations
- Audit existing Subscriber accounts and remove any created by unknown or suspicious sources
- Rotate administrator email addresses if phishing or targeted outreach is observed following disclosure
Patch Information
The vendor addressed the issue in User Private Files version 2.1.9. The patch adds validation ensuring that the supplied user is associated with the document being operated on before returning the user's email address. Administrators should verify the installed version through the WordPress plugin management console.
Workarounds
- Disable the User Private Files plugin until the patch can be applied
- Restrict new user registration on affected WordPress sites to reduce the pool of accounts that can authenticate
- Place the plugin's endpoints behind a web application firewall rule that limits request rates per authenticated session
# Verify installed plugin version via WP-CLI
wp plugin get user-private-files --field=version
# Update to the patched release
wp plugin update user-private-files --version=2.1.9
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.