Vulnerabilities > Mediajedi > User Private Files

DATE CVE VULNERABILITY TITLE RISK
2024-08-22 CVE-2024-7848 Authorization Bypass Through User-Controlled Key vulnerability in Mediajedi User Private Files
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key.
network
low complexity
mediajedi CWE-639
6.5