Impact
The Shared Files plugin versions up to 1.7.69 contain a Server Side Request Forgery vulnerability that allows an attacker to cause the plugin to perform arbitrary HTTP requests from the WordPress server. This flaw can leak internal network resources, fetch sensitive data, or trigger unintended actions on backend services that are reachable from the server. The problem is defined as CWE-918 and is measured by a CVSS score of 6.4, indicating a moderate likelihood of impacting confidentiality, integrity, or availability when exploited.
Affected Systems
All installations of Tammersoft Shared Files plugin at or below version 1.7.69 are affected. The plugin in question is a WordPress add‑on used to manage and serve files from the server.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity; however no EPSS data is available. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploits at this time. The attack vector is likely remote, requiring an attacker to interact with the plugin’s settings or error handling paths, after which the server will attempt outbound connections to arbitrary URLs supplied by the attacker. The partial absence of exploitation metrics indicates that while the flaw is exploitable, success depends on the server’s network configuration and the attacker’s ability to craft suitable requests. Nonetheless, the potential for internal disclosure or remote service manipulation warrants swift remediation.
OpenCVE Enrichment