Junglewise Threat Intelligence

CVE-2026-80494: Yogeta WP Cloud arbitrary file download

CVE-2026-80494 · Severity: high · CVSS 8.6 · Published 2026-09-12

Executive brief

The Yogeta WP Cloud WordPress plugin is a file storage/management tool for WordPress sites. An unauthenticated attacker can download any file from the server without logging in, including sensitive configuration files containing database passwords and API keys, leading to complete compromise of the website and underlying infrastructure.

Technical details

The vulnerability is an unauthenticated arbitrary file download (CWE-552) caused by insufficient input validation. A public endpoint in the plugin passes user-supplied file paths directly to a file-read function without sanitizing the path or checking authorization. An attacker can exploit this by sending requests to the public endpoint with path traversal sequences (e.g., ../../../etc/passwd) to read arbitrary files. No authentication is required and the attack is trivial to execute. No fix is currently available as of the advisory publication date.

Affected products

  • Yogeta WP Cloud through 1.0

Timeline

  • 2026-09-10: disclosed: Publicly published on WPScan
  • 2026-09-12: other: Added to NVD

References