CVE-2026-19084

Published: Ago 28, 2026 Last Modified: Ago 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.

https://wpscan.com/vulnerability/48b86169-5ccf-4111-be15-9dd45d478465/