SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-80494

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Yogeta WP Cloud plugin for WordPress versions up to 1.0 is vulnerable due to improper validation of user-supplied file paths, enabling unauthenticated attackers to exploit a public endpoint and download arbitrary files from the server. This flaw poses a significant risk as it can expose sensitive information, including credentials. WordPress site administrators using this plugin should prioritize immediate remediation to mitigate potential data breaches.

CVE
CVE-2026-80494
Severity
HIGH
CVSS
8.6
EPSS
0.32%
WordPress

Original NVD Description

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.