CVE-2026-78269
Received Received - Intake

Contributor SSRF in Shared Files <= 1.7.69

Vulnerability report for CVE-2026-78269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Patchstack

Description

Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack shared_files_plugin to 1.7.69 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Server Side Request Forgery (SSRF) in the WordPress Shared Files Plugin versions 1.7.69 and below. It allows attackers with contributor-level access to make the website send requests to arbitrary domains, potentially exposing sensitive information from other services on the same system.

Detection Guidance

To detect this SSRF vulnerability in the Shared Files plugin, check the installed version of the plugin via WordPress admin panel or database. Compare it against version 1.7.69. Look for unusual outbound requests from your server to external domains in web server logs.

Impact Analysis

An attacker could exploit this to access internal services or sensitive data on the server, leading to data breaches or unauthorized actions. The impact is considered low severity but could still compromise system integrity and confidentiality.

Compliance Impact

This SSRF vulnerability could expose sensitive information from other services on the same system, which may include personal data regulated by GDPR or HIPAA. Unauthorized access to such data could lead to compliance violations if proper safeguards are not in place.

Mitigation Strategies

Immediately update the Shared Files plugin to version 1.7.70 or later. If updating is not possible, disable the plugin temporarily until you can apply the patch. Enable auto-updates for the plugin if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78269. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart