๐Ÿ” CVE Alert

CVE-2026-12513

UNKNOWN 0.0

Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.

Vendor unknown
Product shared files
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown shared files

Be the first to know when new unknown vulnerabilities affecting unknown shared files are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Shared Files
0 < 1.7.67
Unknown / shared-files-pro
0 < 1.7.68

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/25c9fa21-c48b-4333-8abc-87230dc4c869/

Credits

Huynh Kien Minh WPScan