Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High1
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-02-19

CVE-2024-13799 - User Private Files Plugin

The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN User Private Files

CVE-2024-13799

MEDIUM CVSS 6.4 2025-02-19
Threat Entry Updated 2024-09-26

CVE-2024-7848 - User Private Files Plugin

The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to gain access to other user's private files.

PLUGIN User Private Files

CVE-2024-7848

MEDIUM CVSS 4.3 2024-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2356 - User Private Files Plugin

The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

PLUGIN User Private Files

CVE-2022-2356

HIGH CVSS 8.8 2022-08-08
Scroll to top