sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total13
Critical0
High3
Medium10
Reset
Showing 1-13 of 13 records
Threat Entry Updated 2026-08-28

Shared Files - Denial of Service (CVE-2026-12513)

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.

PLUGIN Shared Files

CVE-2026-12513

MEDIUM CVSS 6.8 2026-08-28
Threat Entry Updated 2026-08-28

Shared Files - Security Vulnerability (CVE-2026-12514)

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded.

PLUGIN Shared Files

CVE-2026-12514

MEDIUM CVSS 5.3 2026-08-28
Threat Entry Updated 2026-06-17

Shared Files - Arbitrary File Upload (CVE-2025-4392)

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible for unauthenticated attackers to bypass the plugin’s MIME-only checks and inject arbitrary web scripts in pages that will execute whenever a user accesses the html file.

PLUGIN Shared Files

CVE-2025-4392

HIGH CVSS 7.2 2025-06-03
Threat Entry Updated 2026-06-17

Shared Files - Arbitrary File Upload (CVE-2024-13504)

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the dfxp file. This issue affects only Apache-based environments, where dfxp files are handled by default.

PLUGIN Shared Files

CVE-2024-13504

HIGH CVSS 7.2 2025-01-31
Threat Entry Updated 2026-06-17

Shared Files - Arbitrary File Upload (CVE-2023-4819)

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

PLUGIN Shared Files

CVE-2023-4819

MEDIUM CVSS 6.1 2023-10-16
Threat Entry Updated 2026-06-17

Shared Files - Cross-Site Scripting (XSS) (CVE-2021-24856)

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Shared Files

CVE-2021-24856

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2026-06-17

Shared Files - Arbitrary File Upload (CVE-2021-24736)

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

PLUGIN Shared Files

CVE-2021-24736

MEDIUM CVSS 4.8 2021-10-18