VYPR

shared-files-pro

by WordPress

CVEs (3)

  • CVE-2026-19084Aug 28, 2026
    risk 0.00cvss epss

    The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.

  • CVE-2026-12514Aug 28, 2026
    risk 0.00cvss epss

    The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an…

  • CVE-2026-12513Aug 28, 2026
    risk 0.00cvss epss

    The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that…