WordPress Plugin Vulnerabilities

Shared Files < 1.7.70 - Unauthenticated Limited File Upload

Description

The plugins do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded.

Proof of Concept

Affects Plugins

Fixed in 1.7.67
Fixed in 1.7.70

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
hoangphuong
Submitter
hoangphuong
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-26 (about 2 days ago)
Added
2026-08-26 (about 1 day ago)
Last Updated
2026-08-26 (about 1 day ago)

Other