CVE-2026-12514
Shared Files < 1.7.70 - Unauthenticated Limited File Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded.
| Vendor | unknown |
| Product | shared files |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown shared files
Be the first to know when new unknown vulnerabilities affecting unknown shared files are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Shared Files
0 < 1.7.67
Unknown / shared-files-pro
0 < 1.7.70
References
Credits
hoangphuong WPScan