The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Mar 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector | |
| Title | Shared Files < 1.7.58 - Contributor+ Arbitrary File Download | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-03-26T06:00:07.315Z
Reserved: 2026-01-01T13:42:06.702Z
Link: CVE-2025-15433
No data.
Status : Received
Published: 2026-03-26T07:16:19.133
Modified: 2026-03-26T07:16:19.133
Link: CVE-2025-15433
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.