CVE-2026-78269: WordPress Shared Files plugin <= 1.7.69 - Server Side Request Forgery (SSRF) vulnerability
Published Aug 24, 2026
·Updated
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
Affected Software
1 affected component
WordPress Shared Files plugin<=1.7.69
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Shared Files Pluginto a version that resolves this vulnerability.Fixed in 1.7.70
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level privileges. No user interaction is required, and the attack can be performed remotely.
2
What security impact can successful exploitation have?
The vulnerability can allow server-side requests that affect confidentiality and integrity. The reported CVSS vector indicates low confidentiality and integrity impact, with no availability impact.
3
Which versions are affected?
Shared Files plugin versions 1.7.69 and earlier are affected.