๐Ÿ” CVE Alert

CVE-2026-80494

HIGH 8.6

Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

Vendor unknown
Product yogeta wp cloud
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown yogeta wp cloud

Be the first to know when new high vulnerabilities affecting unknown yogeta wp cloud are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Yogeta WP Cloud
0 โ‰ค 1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fdc0fefb-c090-4972-9867-d1090353e40c/

Credits

Huynh Kien Minh WPScan