CyberRota Analysis
AI-GeneratedThe shared-files-pro WordPress plugin prior to version 1.7.70 is vulnerable due to inadequate validation of file paths when creating featured images, enabling unauthenticated attackers to access and read arbitrary files on the server. This flaw could lead to sensitive information disclosure, potentially exposing critical data to the public. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.