CVE-2026-80494
Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
| Vendor | unknown |
| Product | yogeta wp cloud |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown yogeta wp cloud
Be the first to know when new high vulnerabilities affecting unknown yogeta wp cloud are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Yogeta WP Cloud
0 โค 1.0
References
Credits
Huynh Kien Minh WPScan