CVE-2026-19084
Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
| Vendor | unknown |
| Product | shared-files-pro |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown shared-files-pro
Be the first to know when new unknown vulnerabilities affecting unknown shared-files-pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / shared-files-pro
0 < 1.7.70
References
Credits
Erwan LR (WPScan) WPScan