Junglewise Threat Intelligence

CVE-2026-12513: WordPress Shared Files path traversal arbitrary file deletion

CVE-2026-12513 · Severity: medium · CVSS 6.8 · Published 2026-08-28

Vendors: WordPress.org.

Executive brief

The Shared Files and Shared Files Pro WordPress plugins allow unauthenticated visitors to upload files through a public frontend form. Due to improper path sanitization, attackers can trick the plugins into storing references to files outside the intended upload directory (such as wp-config.php). When a site administrator later deletes these malicious file entries, arbitrary files on the server are permanently deleted, leading to site outages or complete site takeover.

Technical details

The vulnerability is a path traversal flaw in file submission handling. The vulnerable component uses a single-pass str_replace('../','') filter to sanitize file paths, which can be bypassed using encoded traversal sequences like "....//". An unauthenticated attacker can POST a crafted file path via the frontend uploader's admin-ajax action without authentication. The path is stored in a shared_file database entry while bypassing containment checks. During permanent deletion (when admins empty trash or WordPress auto-purge runs), the inadequate filter collapses the payload back into a valid traversal sequence, and the deletion routine resolves to and removes the target file outside wp-content/uploads/. The attack requires the frontend uploader shortcode to be active and accessible to unauthenticated users (the default configuration). Patches are available in Shared Files 1.7.67+ and Shared Files Pro 1.7.68+.

Affected products

  • WordPress.org Shared Files before 1.7.67
  • WordPress.org Shared Files Pro before 1.7.68

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Shared Files 1.7.67 and Shared Files Pro 1.7.68

References