Description
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
Published: 2026-08-24
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Shared Files plugin versions up to 1.7.69 contain a Server Side Request Forgery vulnerability that allows an attacker to cause the plugin to perform arbitrary HTTP requests from the WordPress server. This flaw can leak internal network resources, fetch sensitive data, or trigger unintended actions on backend services that are reachable from the server. The problem is defined as CWE-918 and is measured by a CVSS score of 6.4, indicating a moderate likelihood of impacting confidentiality, integrity, or availability when exploited.

Affected Systems

All installations of Tammersoft Shared Files plugin at or below version 1.7.69 are affected. The plugin in question is a WordPress add‑on used to manage and serve files from the server.

Risk and Exploitability

The CVSS score of 6.4 reflects a moderate severity; however no EPSS data is available. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploits at this time. The attack vector is likely remote, requiring an attacker to interact with the plugin’s settings or error handling paths, after which the server will attempt outbound connections to arbitrary URLs supplied by the attacker. The partial absence of exploitation metrics indicates that while the flaw is exploitable, success depends on the server’s network configuration and the attacker’s ability to craft suitable requests. Nonetheless, the potential for internal disclosure or remote service manipulation warrants swift remediation.

Generated by OpenCVE AI on August 24, 2026 at 12:23 UTC.

Remediation

Vendor Solution

Update the WordPress Shared Files Plugin to the latest available version (at least 1.7.70).


OpenCVE Recommended Actions

  • Update the Shared Files plugin to version 1.7.70 or later.
  • Discontinue use of the plugin or uninstall it if the functionality is not required.
  • If the plugin must remain, limit outbound traffic from the WordPress installation using a firewall or network policy to restrict requests to approved destinations.

Generated by OpenCVE AI on August 24, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Tammersoft
Tammersoft shared Files
Wordpress
Wordpress wordpress
Vendors & Products Tammersoft
Tammersoft shared Files
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
Title WordPress Shared Files plugin <= 1.7.69 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Tammersoft Shared Files
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T11:39:36.942Z

Reserved: 2026-08-24T07:37:56.725Z

Link: CVE-2026-78269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T12:16:54.893

Modified: 2026-08-24T12:16:54.893

Link: CVE-2026-78269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T12:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)