CVE-2026-80494 PUBLISHED

Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download

Assigner: WPScan
Reserved: 26.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

Product Status

Vendor Unknown
Product Yogeta WP Cloud
Versions Default: unknown
  • affected from 0 to 1.0 (incl.)

Credits

  • Huynh Kien Minh finder
  • WPScan coordinator

References

Problem Types

  • CWE-552 Files or Directories Accessible to External Parties CWE