Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 CWE-284 |
Sat, 12 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-552 | |
| Metrics |
cvssV3_1
|
Sat, 12 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 CWE-284 |
Sat, 12 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials. | |
| Title | Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-12T15:34:21.586Z
Reserved: 2026-08-26T13:47:33.757Z
Link: CVE-2026-80494
Updated: 2026-09-12T15:23:31.894Z
Status : Received
Published: 2026-09-12T06:16:25.510
Modified: 2026-09-12T16:16:39.867
Link: CVE-2026-80494
No data.
OpenCVE Enrichment
Updated: 2026-09-12T18:15:19Z
-
CWE-552
Files or Directories Accessible to External Parties