shared-files-pro WordPress 插件在 1.7.70 之前的版本,在创建精选图片时未对所提供的文件路径进行验证,使得未认证的 attackers 能够读取服务器上的任意文件,并将其内容重新发布到一个公共 URL。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | shared-files-pro | < 1.7.70 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | shared-files-pro | 0 ~ 1.7.70 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79996 | User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Sett | |
| CVE-2026-77701 | WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders | |
| CVE-2026-19423 | Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Pr | |
| CVE-2026-79706 | Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal | |
| CVE-2026-79995 | User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via | |
| CVE-2026-79615 | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Dis | |
| CVE-2026-14567 | WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Direc | |
| CVE-2026-14558 | WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder | |
| CVE-2026-12514 | Shared Files < 1.7.70 - Unauthenticated Limited File Upload | |
| CVE-2026-12513 | Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal |
No comments yet