Vulnerability Description
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-80494?
CVE-2026-80494 is a vulnerability with a CVSS score of 8.6 (HIGH). The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing...
How severe is CVE-2026-80494?
CVE-2026-80494 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-80494?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.