CVE-2026-19084
Description
AI Translation Available
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
https://wpscan.com/vulnerability/48b86169-5ccf-4111-be15-9dd45d478465/