Description
Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the WordPress Sell Downloads plugin to the latest available version (at least 1.2.4).
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 10 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3. | |
| Title | WordPress Sell Downloads plugin <= 1.2.3 - Broken Access Control vulnerability | |
| Weaknesses | CWE-940 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-10T18:45:46.475Z
Reserved: 2026-09-21T21:08:52.159Z
Link: CVE-2026-94590
No data.
Status : Received
Published: 2026-10-10T19:16:58.917
Modified: 2026-10-10T19:16:58.917
Link: CVE-2026-94590
No data.
OpenCVE Enrichment
No data.
Weaknesses