CVE-2026-19084: Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker does not need to authenticate. Any deployment running a vulnerable version of the shared-files-pro plugin may be exposed if the affected featured-image creation functionality is reachable.
What can an attacker obtain?
An attacker can supply an arbitrary server file path when creating a featured image. The file's contents can then be republished at a public URL, potentially exposing data readable by the web server process.
How can I determine whether my site is affected?
Check the installed shared-files-pro plugin version. Versions before 1.7.70 are affected; version 1.7.70 or later is not identified as affected by the provided information.