CVE-2026-94590
Received Received - Intake

Improper Verification of Trusted Credentials in Sell Downloads

Vulnerability report for CVE-2026-94590, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Patchstack

Description

Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CodePeople2 Sell Downloads 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-940 The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Verification of Source of a Communication Channel issue in the CodePeople2 Sell Downloads plugin. It allows attackers to exploit trusted credentials due to insufficient validation of communication sources. The flaw exists in versions up to 1.2.3.

Impact Analysis

An attacker could impersonate a trusted source to gain unauthorized access or manipulate transactions. This may lead to data leaks, financial loss, or unauthorized changes in the Sell Downloads plugin.

Mitigation Strategies

Update Sell Downloads to the latest version (1.2.3 or later) to address the improper verification issue. Disable or restrict access to the affected plugin if an update is not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94590. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart