SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19084

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The shared-files-pro WordPress plugin prior to version 1.7.70 is vulnerable due to inadequate validation of file paths when creating featured images, enabling unauthenticated attackers to access and read arbitrary files on the server. This flaw could lead to sensitive information disclosure, potentially exposing critical data to the public. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-19084
Severity
HIGH
CVSS
7.5
EPSS
0.32%
WordPress

Original NVD Description

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.