The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-12 06:16
Updated : 2026-09-14 21:10
NVD link : CVE-2026-80494
Mitre link : CVE-2026-80494
CVE.ORG link : CVE-2026-80494
JSON object : View
Products Affected
No product.
CWE
CWE-552
Files or Directories Accessible to External Parties
