CVE-2026-12513
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.
| Vendor | unknown |
| Product | shared files |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown shared files
Be the first to know when new unknown vulnerabilities affecting unknown shared files are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Shared Files
0 < 1.7.67
Unknown / shared-files-pro
0 < 1.7.68
References
Credits
Huynh Kien Minh WPScan