Executive brief
The Shared Files WordPress plugin before version 1.7.70 contains a Server-Side Request Forgery (SSRF) vulnerability that allows attackers with contributor-level access to force the server to make HTTP requests to internal systems. This could enable attackers to access sensitive data behind the firewall, such as internal databases, APIs, or configuration systems not normally exposed to the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Shared Files WordPress plugin versions 1.7.69 and earlier. The vulnerability allows attackers with contributor-level WordPress privileges to craft malicious requests that cause the server to connect to arbitrary internal network resources. The attack vector is network-based and requires authenticated access (contributor role or higher). An attacker can leverage this to access internal systems behind the firewall, potentially extracting sensitive data. The vulnerability has been patched in version 1.7.70.
Affected products
- Tammersoft Shared Files <=1.7.69
Timeline
- 2026-08-24: disclosed: Published by Patchstack
- 2026-08-24: patched: Version 1.7.70 released