← WordPress Vulnerabilities
WordPress security by component

Yogeta WP Cloud

Yogeta WP Cloud (yogeta-wp-cloud) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.6.

Plugin slug: yogeta-wp-cloud

CVE-2026-80494: Yogeta WP Cloud exposes unauthenticated arbitrary file reads

Yogeta WP Cloud through 1.0 passes a caller-controlled path from a public endpoint to a file-read operation without authorization or path validation. An unauthenticated attacker can download arbitrary server files, including configuration files containing credentials. The authoritative export does not name the endpoint, path parameter, or file-read function.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for yogeta-wp-cloud
Safe version
Sep 12, 2026 CVE-2026-80494
Yogeta WP Cloud exposes unauthenticated arbitrary file reads
Yogeta WP Cloud through 1.0 passes a caller-controlled path from a public endpoint to a file-read operation without authorization or path validation. An unauthenticated attacker can download arbitrary server files, including configuration files containing credentials. The authoritative export does not name the endpoint, path parameter, or file-read function.
See mitigation notes
CVE8.6
NVDPending