Junglewise Threat Intelligence

CVE-2026-10093: WordPress User Private Files Stored XSS in fldr_ttl parameter

CVE-2026-10093 · Severity: medium · CVSS 6.4 · Published 2026-06-16

Vendors: Wordpress.

Executive brief

A vulnerability exists in a WordPress plugin used for managing private user files and folders. An attacker with basic user access can inject malicious scripts into the website's pages. When other users or administrators visit those pages, the scripts will run automatically, potentially allowing the attacker to steal session information or perform unauthorized actions on behalf of the victim.

Technical details

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'fldr_ttl' parameter. This vulnerability allows authenticated attackers with subscriber-level permissions or higher to inject arbitrary web scripts into the database. These scripts are then executed in the browser of any user who accesses the affected page. The issue is present in all versions up to 2.1.6 and was addressed in version 2.1.7.

Affected products

  • WordPress File Sharing & Download Manager – User Private Files up to, and including, 2.1.6

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References