VYPR

User Private Files

by WordPress

Source repositories

CVEs (3)

  • CVE-2026-10093MedJun 16, 2026
    risk 0.35cvss 6.4epss 0.00

    The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2024-13799MedFeb 19, 2025
    risk 0.35cvss 6.4epss 0.00

    The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and…

  • CVE-2024-7848MedAug 22, 2024
    risk 0.28cvss 4.3epss 0.00

    The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it…