Shared Files – File Upload & Download Manager <= 1.7.69 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Shared Files – File Upload & Download Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.69. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the...
- CVSS:
- 6.4
- Affected:
- up to 1.7.69
- Fixed in:
- 1.7.70
- Disclosed:
- Aug 24, 2026
CVE-2026-78269 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 - Unauthenticated Path Traversal
medium
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.64. This makes it possible for unauthenticated attackers to perform actions on files outside of the originally intended directory.
- CVSS:
- 5.3
- Affected:
- up to 1.7.64
- Fixed in:
- 1.7.65
- Disclosed:
- Jun 5, 2026
CVE-2026-49112 on NVD →
Shared Files - Contributor+ Arbitrary File Download vulnerability
medium
Contributor+ Arbitrary File Download vulnerability
- CVSS:
- 6.5
- Affected:
- up to 1.7.58
- Fixed in:
- 1.7.58
- Disclosed:
- Mar 30, 2026
Shared Files – Frontend File Upload Form & Secure File Sharing < 1.7.58 - Authenticated (Contributor+) Arbitrary File Download
medium
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversal in all versions up to 1.7.58 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can...
- CVSS:
- 4.3
- Affected:
- up to 1.7.58
- Fixed in:
- 1.7.58
- Disclosed:
- Mar 30, 2026
CVE-2025-15433 on NVD →
Shared Files <= 1.7.48 - Unauthenticated Stored Cross-Site Scripting via sanitize_file Function
high
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible f...
- CVSS:
- 7.2
- Affected:
- up to 1.7.48
- Fixed in:
- 1.7.49
- Disclosed:
- Jun 2, 2025
CVE-2025-4392 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.43
unknown
[en] The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 1.7.43
- Fixed in:
- 1.7.43
- Disclosed:
- Jan 31, 2025
CVE-2024-13504 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.42 - Limited Unauthenticated Stored Cross-Site Scripting via File Upload
high
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- CVSS:
- 7.2
- Affected:
- up to 1.7.42
- Fixed in:
- 1.7.43
- Disclosed:
- Jan 30, 2025
CVE-2024-13504 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.6.72
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.29
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Shared Files – File Upload Form Shared Files.This issue affects Shared Files: from n/a through 1.7.28.
- Affected:
- up to 1.7.29
- Fixed in:
- 1.7.29
- Disclosed:
- Aug 26, 2024
CVE-2024-43230 on NVD →
Shared Files <= 1.7.28 - Unauthenticated Sensitive Information Exposure
medium
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.28 via the export functionality and lack of protected directory. This makes it possible for unauthenticated attackers to extract sensitive dat...
- CVSS:
- 5.3
- Affected:
- up to 1.7.28
- Fixed in:
- 1.7.29
- Disclosed:
- Aug 9, 2024
CVE-2024-43230 on NVD →
Shared Files <= 1.7.19 - Missing Authorization
medium
The Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads & Lead Generation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.19. This makes it possible for unauthenticated attackers to perform an u...
- CVSS:
- 5.3
- Affected:
- up to 1.7.19
- Fixed in:
- 1.7.20
- Disclosed:
- May 7, 2024
CVE-2024-34438 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.17
unknown
[en] Missing Authorization vulnerability in Shared Files PRO Shared Files.This issue affects Shared Files: from n/a through 1.7.16.
- Affected:
- up to 1.7.17
- Fixed in:
- 1.7.17
- Disclosed:
- Apr 23, 2024
CVE-2024-32679 on NVD →
Shared Files <= 1.7.16 - Missing Authorization to Notice Dismissal
medium
The Shared Files plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_notifications function in versions up to, and including, 1.7.16. This makes it possible for unauthenticated attackers to dismiss notices.
- CVSS:
- 5.3
- Affected:
- up to 1.7.16
- Fixed in:
- 1.7.17
- Disclosed:
- Apr 17, 2024
CVE-2024-32679 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.6
unknown
[en] The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Oct 16, 2023
CVE-2023-4819 on NVD →
Shared Files <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting
high
The Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded file content in all versions up to, and including, 1.7.5 due to the plugin not returning the correct 'Content-Type' header when viewing uploaded files. This ma...
- CVSS:
- 7.2
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.6
- Disclosed:
- Sep 21, 2023
CVE-2023-4819 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.6.23 – 1.6.99
- Fixed in:
- 1.7.3
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.6.72
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Mar 4, 2022
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.6.72
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Shared Files plugin (versions < 1.6.72).
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Feb 28, 2022
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.6.72
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Shared Files plugin (versions < 1.6.72).
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Feb 28, 2022
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.6.72
unknown
[en] The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Nov 17, 2021
CVE-2021-24856 on NVD →
Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload <= 1.6.60 - Cross-Site Scripting
medium
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.6.61
- Fixed in:
- 1.6.61
- Disclosed:
- Oct 18, 2021
CVE-2021-24856 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.6.72
unknown
[en] The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.72
- Disclosed:
- Oct 18, 2021
CVE-2021-24736 on NVD →
Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload <= 1.6.56 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.
- CVSS:
- 4.8
- Affected:
- up to 1.6.57
- Fixed in:
- 1.6.57
- Disclosed:
- Sep 15, 2021
CVE-2021-24736 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
CVE-2023-33999 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.20
unknown
- Affected:
- up to 1.7.20
- Fixed in:
- 1.7.20
CVE-2024-34438 on NVD →
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] < 1.7.49
unknown
- Affected:
- up to 1.7.49
- Fixed in:
- 1.7.49
CVE-2025-4392 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database