File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter
medium
The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscri...
- CVSS:
- 6.4
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Jun 15, 2026
CVE-2026-10093 on NVD →
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 2.1.4
unknown
[en] The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for aut...
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Feb 19, 2025
CVE-2024-13799 on NVD →
User Private Files – File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
- CVSS:
- 6.4
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.4
- Disclosed:
- Feb 18, 2025
CVE-2024-13799 on NVD →
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 2.1.1
unknown
[en] The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, w...
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Aug 22, 2024
CVE-2024-7848 on NVD →
User Private Files <= 2.1.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access
medium
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with s...
- CVSS:
- 4.3
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Aug 21, 2024
CVE-2024-7848 on NVD →
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 2.0.5
unknown
[en] The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Oct 31, 2023
CVE-2023-4836 on NVD →
User Private Files < 2.0.5 - Insecure Direct Object Reference
medium
The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.0.5 (exclusive) via the upvf_pro_preview_file function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to gain access to files and fol...
- CVSS:
- 5.3
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Oct 11, 2023
CVE-2023-4836 on NVD →
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 2.0.4
unknown
[en] The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abo...
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Sep 5, 2023
CVE-2023-4636 on NVD →
WordPress File Sharing Plugin <= 2.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, t...
- CVSS:
- 4.4
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Sep 4, 2023
CVE-2023-4636 on NVD →
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 1.1.3
unknown
[en] The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.3
- Disclosed:
- Aug 8, 2022
CVE-2022-2356 on NVD →
Frontend File Manager & Sharing – User Private Files <= 1.1.1 - Missing Authorization
medium
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions such as dpk_upvf_rmv_file(), dpk_upvf_rmv_access(), and dpk_upvf_update_doc(). T...
- CVSS:
- 6.3
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Aug 6, 2022
Frontend File Manager & Sharing – User Private Files <= 1.1.0 - Sensitive Information Disclosure
medium
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.0 via the dpk_upvf_uemail_search() function. This can allow unauthenticated attackers to extract sensitive data including user emails.
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Aug 6, 2022
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 1.1.2
unknown
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions such as dpk_upvf_rmv_file(), dpk_upvf_rmv_access(), and dpk_upvf_update_doc(). T...
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Aug 6, 2022
User Private Files – File Upload & Download Manager with Secure File Sharing [user-private-files] < 1.1.1
unknown
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.0 via the dpk_upvf_uemail_search() function. This can allow unauthenticated attackers to extract sensitive data including user emails.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Aug 6, 2022
Frontend File Manager & Sharing – User Private Files <= 1.1.2 - Subscriber+ Arbitrary File Upload
high
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_doc_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber level permissions and...
- CVSS:
- 8.8
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.3
- Disclosed:
- Jul 11, 2022
CVE-2022-2356 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database