Executive brief
The Shared Files and Shared Files Pro WordPress plugins allow unauthenticated visitors to upload files through a public frontend form. Due to improper path sanitization, attackers can trick the plugins into storing references to files outside the intended upload directory (such as wp-config.php). When a site administrator later deletes these malicious file entries, arbitrary files on the server are permanently deleted, leading to site outages or complete site takeover.
Technical details
The vulnerability is a path traversal flaw in file submission handling. The vulnerable component uses a single-pass str_replace('../','') filter to sanitize file paths, which can be bypassed using encoded traversal sequences like "....//". An unauthenticated attacker can POST a crafted file path via the frontend uploader's admin-ajax action without authentication. The path is stored in a shared_file database entry while bypassing containment checks. During permanent deletion (when admins empty trash or WordPress auto-purge runs), the inadequate filter collapses the payload back into a valid traversal sequence, and the deletion routine resolves to and removes the target file outside wp-content/uploads/. The attack requires the frontend uploader shortcode to be active and accessible to unauthenticated users (the default configuration). Patches are available in Shared Files 1.7.67+ and Shared Files Pro 1.7.68+.
Affected products
- WordPress.org Shared Files before 1.7.67
- WordPress.org Shared Files Pro before 1.7.68
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Shared Files 1.7.67 and Shared Files Pro 1.7.68