Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update the WordPress Sell Downloads plugin to the latest available version (at least 1.2.4).
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3. | |
| Title | WordPress Sell Downloads plugin <= 1.2.3 - Broken Access Control vulnerability | |
| Weaknesses | CWE-940 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-10T18:45:46.475Z
Reserved: 2026-09-21T21:08:52.159Z
Link: CVE-2026-94590
No data.
Status : Received
Published: 2026-10-10T19:16:58.917
Modified: 2026-10-10T19:16:58.917
Link: CVE-2026-94590
No data.
OpenCVE Enrichment
No data.
Weaknesses