CVE-2026-19084 PUBLISHED

Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read

Assigner: WPScan
Reserved: 06.08.2026 Published: 28.08.2026 Updated: 28.08.2026

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.

Product Status

Vendor Unknown
Product shared-files-pro
Versions Default: unaffected
  • affected from 0 to 1.7.70 (excl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE