Extension WordPress
Vulnérabilités Secure Client Portal and Private File Sharing Plugin – User Private Files
Cette page rassemble les failles publiées pour Secure Client Portal and Private File Sharing Plugin – User Private Files, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Secure Client Portal and Private File Sharing Plugin – User Private Files
8 fiches
File Sharing & Download Manager <= 2.1.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter
The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output…
*-2.1.6
2.1.7
15/06/2026
User Private Files – File Upload & Download Manager with Secure File Sharing <= 2.1.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient…
*-2.1.3
2.1.4
18/02/2025
User Private Files <= 2.1.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user…
*-2.1.0
2.1.1
21/08/2024
User Private Files < 2.0.5 – Insecure Direct Object Reference
The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.0.5 (exclusive) via the upvf_pro_preview_file function due to missing validation on a user controlled key. This makes it…
[*, 2.0.5)
2.0.5
11/10/2023
WordPress File Sharing Plugin <= 2.0.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.0.3
2.0.4
04/09/2023
Frontend File Manager & Sharing – User Private Files <= 1.1.0 – Sensitive Information Disclosure
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.0 via the dpk_upvf_uemail_search() function. This can allow unauthenticated attackers to extract sensitive…
*-1.1.0
1.1.1
06/08/2022
Frontend File Manager & Sharing – User Private Files <= 1.1.1 – Missing Authorization
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions…
*-1.1.1
1.1.2
06/08/2022
Frontend File Manager & Sharing – User Private Files <= 1.1.2 – Subscriber+ Arbitrary File Upload
The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_doc_callback function in versions up to, and including, 1.1.2. This makes…
*-1.1.2
1.1.3
11/07/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.