---
id: CVE-2026-97332
title: >-
  The User Private Files  WordPress plugin before 2.2.0 does not properly
  protect its stored private files on multisite installations, where the rewrite
  rule it relies on to route file requests through its access check is never
  reached, al…
summary: >-
  The User Private Files  WordPress plugin before 2.2.0 does not properly
  protect its stored private files on multisite installations, where the rewrite
  rule it relies on to route file requests through its access check is never
  reached, al…
severity: none
cwe:
  - CWE-284
product: User Private Files
affected:
  - user_private_files < 2.2.0
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T07:16:34.303'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97332'
references:
  - url: 'https://wpscan.com/vulnerability/d6a144b3-84e3-43eb-92d3-fd4505dd0e1c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T06:55:02.311Z'
---

## Overview

The User Private Files  WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
