Yogeta WP Cloud vulnerability

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

Published 12 Sep 2026Updated 12 Sep 20261 sources
CVSS 0.0

Source timeline

CVE record published by NVDView source ↗