Review reviewHigh
CVE-2026-9690
Joomunited WP Media folder Addon
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
- CVSS
- 7.5
- EPSS
- 0.47% 37.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.17
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
The CVSS severity warrants an early asset and exposure review.
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
Confirm exposure before applying a vendor-supported change.
Confirm that Joomunited WP Media folder Addon and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.