Executive brief
Youzify is a WordPress plugin that provides community and membership functionality. A vulnerability in versions 1.3.7 and earlier allows any subscriber-level user to download arbitrary files from the server, potentially exposing sensitive data such as configuration files, database backups, or private keys that could compromise the entire WordPress installation and hosted applications.
Technical details
The vulnerability is an arbitrary file download flaw (OWASP A1: Broken Access Control) in Youzify versions up to 1.3.7. It allows authenticated users with subscriber privileges to access and download files without proper authorization checks. The vulnerability requires authentication as a subscriber-level WordPress user but does not require elevated privileges, making it exploitable by low-privilege accounts. No official patch is currently available as of the advisory date. Attackers can leverage this to exfiltrate sensitive server files, configuration data, and credentials.
Affected products
- Youzify Youzify <=1.3.7
Timeline
- 2026-09-08: disclosed
- 2026-09-10: advisory