Home

Description

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to download files uploaded by others users and expose potentially sensitive information.

PUBLISHED Reserved 2024-09-18 | Published 2025-05-14 | Updated 2026-04-08 | Assigner Wordfence




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version
affected

Timeline

2025-02-27:Vendor Notified
2025-05-13:Disclosed

Credits

Bikram Kharal finder

References

www.wordfence.com/...-655c-41d5-a3c5-6b36fbff58dc?source=cve

www.peepso.com/changelog/

cve.org (CVE-2024-8988)

nvd.nist.gov (CVE-2024-8988)

Download JSON