Extension WordPress
Vulnérabilités Shared Files – File Upload & Download Manager
Cette page rassemble les failles publiées pour Shared Files – File Upload & Download Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Shared Files – File Upload & Download Manager
12 fiches
Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 – Unauthenticated Path Traversal
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.64. This makes it possible for unauthenticated attackers to perform actions…
*-1.7.64
1.7.65
05/06/2026
Shared Files – Frontend File Upload Form & Secure File Sharing < 1.7.58 – Authenticated (Contributor+) Arbitrary File Download
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversal in all versions up to 1.7.58 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and…
[*, 1.7.58)
1.7.58
30/03/2026
Shared Files <= 1.7.48 – Unauthenticated Stored Cross-Site Scripting via sanitize_file Function
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization…
*-1.7.48
1.7.49
02/06/2025
Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.42 – Limited Unauthenticated Stored Cross-Site Scripting via File Upload
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization…
*-1.7.42
1.7.43
30/01/2025
Shared Files <= 1.7.28 – Unauthenticated Sensitive Information Exposure
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.28 via the export functionality and lack of protected directory.…
*-1.7.28
1.7.29
09/08/2024
Shared Files <= 1.7.19 – Missing Authorization
The Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads & Lead Generation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…
*-1.7.19
1.7.20
07/05/2024
Shared Files <= 1.7.16 – Missing Authorization to Notice Dismissal
The Shared Files plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_notifications function in versions up to, and including, 1.7.16. This makes it possible for unauthenticated attackers to…
*-1.7.16
1.7.17
17/04/2024
Shared Files <= 1.7.5 – Unauthenticated Stored Cross-Site Scripting
The Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded file content in all versions up to, and including, 1.7.5 due to the plugin…
*-1.7.5
1.7.6
21/09/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.6.23-1.6.99
1.7.3
18/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.6.72)
1.6.72
04/03/2022
Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload <= 1.6.60 – Cross-Site Scripting
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
[*, 1.6.61)
1.6.61
18/10/2021
Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload <= 1.6.56 – Authenticated (Admin+) Stored Cross-Site Scripting
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library , Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes,…
[*, 1.6.57)
1.6.57
15/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.