Extension WordPress

Vulnérabilités Secure Client Portal and Private File Sharing Plugin – User Private Files

Cette page rassemble les failles publiées pour Secure Client Portal and Private File Sharing Plugin – User Private Files, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Secure Client Portal and Private File Sharing Plugin – User Private Files

8 fiches

CVE-2026-10093 Moyenne · 6,4
Secure Client Portal and Private File Sharing Plugin – User Private Files

File Sharing & Download Manager <= 2.1.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output…

Versions affectées

*-2.1.6

Correctif

2.1.7

Publication

15/06/2026

CVE-2024-13799 Moyenne · 6,4
Secure Client Portal and Private File Sharing Plugin – User Private Files

User Private Files – File Upload & Download Manager with Secure File Sharing <= 2.1.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient…

Versions affectées

*-2.1.3

Correctif

2.1.4

Publication

18/02/2025

CVE-2024-7848 Moyenne · 4,3
Secure Client Portal and Private File Sharing Plugin – User Private Files

User Private Files <= 2.1.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access

The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user…

Versions affectées

*-2.1.0

Correctif

2.1.1

Publication

21/08/2024

CVE-2023-4836 Moyenne · 5,3
Secure Client Portal and Private File Sharing Plugin – User Private Files

User Private Files < 2.0.5 – Insecure Direct Object Reference

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.0.5 (exclusive) via the upvf_pro_preview_file function due to missing validation on a user controlled key. This makes it…

Versions affectées

[*, 2.0.5)

Correctif

2.0.5

Publication

11/10/2023

CVE-2023-4636 Moyenne · 4,4
Secure Client Portal and Private File Sharing Plugin – User Private Files

WordPress File Sharing Plugin <= 2.0.3 – Authenticated (Admin+) Stored Cross-Site Scripting

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

04/09/2023

Vulnérabilité Moyenne · 5,3
Secure Client Portal and Private File Sharing Plugin – User Private Files

Frontend File Manager & Sharing – User Private Files <= 1.1.0 – Sensitive Information Disclosure

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.0 via the dpk_upvf_uemail_search() function. This can allow unauthenticated attackers to extract sensitive…

Versions affectées

*-1.1.0

Correctif

1.1.1

Publication

06/08/2022

Vulnérabilité Moyenne · 6,3
Secure Client Portal and Private File Sharing Plugin – User Private Files

Frontend File Manager & Sharing – User Private Files <= 1.1.1 – Missing Authorization

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions…

Versions affectées

*-1.1.1

Correctif

1.1.2

Publication

06/08/2022

CVE-2022-2356 Élevée · 8,8
Secure Client Portal and Private File Sharing Plugin – User Private Files

Frontend File Manager & Sharing – User Private Files <= 1.1.2 – Subscriber+ Arbitrary File Upload

The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_doc_callback function in versions up to, and including, 1.1.2. This makes…

Versions affectées

*-1.1.2

Correctif

1.1.3

Publication

11/07/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités