PT-2025-23588 · WordPress · The Shared Files – Frontend File Upload Form & Secure File Sharing

Martin Martin

·

Published

2025-06-03

·

Updated

2025-06-03

·

CVE-2025-4392

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress versions up to, and including, 1.7.48
Description The issue is related to Stored Cross-Site Scripting via html file uploads due to insufficient input sanitization and output escaping within the sanitize file() function. This allows unauthenticated attackers to bypass the plugin’s MIME-only checks and inject arbitrary web scripts in pages that will execute whenever a user accesses the html file.
Recommendations For versions up to, and including, 1.7.48, update to a version that fixes the insufficient input sanitization and output escaping issue within the sanitize file() function. As a temporary workaround, consider disabling the file upload functionality until a patch is available. Restrict access to uploaded html files to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-4392

Affected Products

The Shared Files – Frontend File Upload Form & Secure File Sharing