Extension WordPress

Vulnérabilités Shared Files – File Upload & Download Manager

Cette page rassemble les failles publiées pour Shared Files – File Upload & Download Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Shared Files – File Upload & Download Manager

12 fiches

CVE-2026-49112 Moyenne · 5,3
Shared Files – File Upload & Download Manager

Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 – Unauthenticated Path Traversal

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.64. This makes it possible for unauthenticated attackers to perform actions…

Versions affectées

*-1.7.64

Correctif

1.7.65

Publication

05/06/2026

CVE-2025-15433 Moyenne · 4,3
Shared Files – File Upload & Download Manager

Shared Files – Frontend File Upload Form & Secure File Sharing < 1.7.58 – Authenticated (Contributor+) Arbitrary File Download

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversal in all versions up to 1.7.58 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

[*, 1.7.58)

Correctif

1.7.58

Publication

30/03/2026

CVE-2025-4392 Élevée · 7,2
Shared Files – File Upload & Download Manager

Shared Files <= 1.7.48 – Unauthenticated Stored Cross-Site Scripting via sanitize_file Function

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization…

Versions affectées

*-1.7.48

Correctif

1.7.49

Publication

02/06/2025

CVE-2024-13504 Élevée · 7,2
Shared Files – File Upload & Download Manager

Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.42 – Limited Unauthenticated Stored Cross-Site Scripting via File Upload

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization…

Versions affectées

*-1.7.42

Correctif

1.7.43

Publication

30/01/2025

CVE-2024-32679 Informationnelle
Shared Files – File Upload & Download Manager

Shared Files <= 1.7.16 – Missing Authorization to Notice Dismissal

The Shared Files plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_notifications function in versions up to, and including, 1.7.16. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.7.16

Correctif

1.7.17

Publication

17/04/2024

CVE-2023-33999 Moyenne · 6,1
Shared Files – File Upload & Download Manager

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

1.6.23-1.6.99

Correctif

1.7.3

Publication

18/07/2023

CVE-2022-4974 Moyenne · 6,3
Shared Files – File Upload & Download Manager

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 1.6.72)

Correctif

1.6.72

Publication

04/03/2022

CVE-2021-24856 Moyenne · 4,8
Shared Files – File Upload & Download Manager

Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload <= 1.6.60 – Cross-Site Scripting

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Versions affectées

[*, 1.6.61)

Correctif

1.6.61

Publication

18/10/2021

CVE-2021-24736 Moyenne · 4,8
Shared Files – File Upload & Download Manager

Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload <= 1.6.56 – Authenticated (Admin+) Stored Cross-Site Scripting

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library , Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes,…

Versions affectées

[*, 1.6.57)

Correctif

1.6.57

Publication

15/09/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités