Userprivatefiles develops a WordPress file-sharing plugin that has surfaced vulnerabilities centered on authorization and input-handling issues, namely authorization-bypass conditions arising from user-controlled key logic and cross-site scripting via improper neutralization of web-page input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Userprivatefiles over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4636MEDIUM The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient i | Sep 5, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-4836MEDIUM The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by ma | Oct 31, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Userprivatefiles.
Media articles that mention a CVE ID that affects a product developed by Userprivatefiles — matched by CVE ID, not by vendor name.