Server Side Request Forgery in Shared Files Plugin by WordPress
CVE-2026-78269

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78269?

The Shared Files plugin for WordPress, specifically versions up to 1.7.69, is susceptible to a Server Side Request Forgery (SSRF) vulnerability. This security flaw allows unauthorized parties to send crafted requests that could potentially access sensitive files on the server. Exploiting this vulnerability could lead to unauthorized access and malicious activities, emphasizing the importance of updating the plugin to secure the environment against potential threats.

Affected Version(s)

Shared Files <= 1.7.69

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cem Bas | Patchstack Bug Bounty Program
.