plugin

User Private Files Vulnerabilities

15 known security issues reported for the User Private Files WordPress plugin. Most recent disclosed Jun 15, 2026.

1 high 7 medium

Running User Private Files on your site? Check whether your installed version is affected.

Scan your site free

File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter

medium

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscri...

CVSS:
6.4
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Jun 15, 2026

CVE-2026-10093 on NVD →

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 2.1.4

unknown

[en] The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Feb 19, 2025

CVE-2024-13799 on NVD →

User Private Files – File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

CVSS:
6.4
Affected:
up to 2.1.3
Fixed in:
2.1.4
Disclosed:
Feb 18, 2025

CVE-2024-13799 on NVD →

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 2.1.1

unknown

[en] The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, w...

Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Aug 22, 2024

CVE-2024-7848 on NVD →

User Private Files <= 2.1.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access

medium

The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with s...

CVSS:
4.3
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Aug 21, 2024

CVE-2024-7848 on NVD →

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 2.0.5

unknown

[en] The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Oct 31, 2023

CVE-2023-4836 on NVD →

User Private Files < 2.0.5 - Insecure Direct Object Reference

medium

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.0.5 (exclusive) via the upvf_pro_preview_file function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to gain access to files and fol...

CVSS:
5.3
Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Oct 11, 2023

CVE-2023-4836 on NVD →

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 2.0.4

unknown

[en] The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abo...

Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Sep 5, 2023

CVE-2023-4636 on NVD →

WordPress File Sharing Plugin <= 2.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, t...

CVSS:
4.4
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Sep 4, 2023

CVE-2023-4636 on NVD →

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 1.1.3

unknown

[en] The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
Aug 8, 2022

CVE-2022-2356 on NVD →

Frontend File Manager & Sharing – User Private Files <= 1.1.1 - Missing Authorization

medium

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions such as dpk_upvf_rmv_file(), dpk_upvf_rmv_access(), and dpk_upvf_update_doc(). T...

CVSS:
6.3
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Aug 6, 2022

Frontend File Manager & Sharing – User Private Files <= 1.1.0 - Sensitive Information Disclosure

medium

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.0 via the dpk_upvf_uemail_search() function. This can allow unauthenticated attackers to extract sensitive data including user emails.

CVSS:
5.3
Affected:
up to 1.1.0
Fixed in:
1.1.1
Disclosed:
Aug 6, 2022

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 1.1.2

unknown

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions such as dpk_upvf_rmv_file(), dpk_upvf_rmv_access(), and dpk_upvf_update_doc(). T...

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Aug 6, 2022

User Private Files &#8211; File Upload &amp; Download Manager with Secure File Sharing [user-private-files] < 1.1.1

unknown

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.0 via the dpk_upvf_uemail_search() function. This can allow unauthenticated attackers to extract sensitive data including user emails.

Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Aug 6, 2022

Frontend File Manager & Sharing – User Private Files <= 1.1.2 - Subscriber+ Arbitrary File Upload

high

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_doc_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber level permissions and...

CVSS:
8.8
Affected:
up to 1.1.2
Fixed in:
1.1.3
Disclosed:
Jul 11, 2022

CVE-2022-2356 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database