Unauthenticated Path Traversal Vulnerability in Shared Files Plugin by WordPress
CVE-2026-49112
7.5HIGH
What is CVE-2026-49112?
The Shared Files plugin for WordPress, specifically versions up to 1.7.64, is susceptible to an unauthenticated path traversal vulnerability. This flaw allows remote attackers to access sensitive files on the server without proper authentication, potentially leading to data leakage and exposure of critical information. Administrators are encouraged to update to the latest version to mitigate this risk.
Affected Version(s)
Shared Files <= 1.7.64