WordPress security by component
Yogeta WP Cloud
Yogeta WP Cloud (yogeta-wp-cloud) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.6.
Plugin slug:
yogeta-wp-cloudLatest vulnerability
CVE-2026-80494: Yogeta WP Cloud exposes unauthenticated arbitrary file reads
Yogeta WP Cloud through 1.0 passes a caller-controlled path from a public endpoint to a file-read operation without authorization or path validation. An unauthenticated attacker can download arbitrary server files, including configuration files containing credentials. The authoritative export does not name the endpoint, path parameter, or file-read function.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-80494
Yogeta WP Cloud exposes unauthenticated arbitrary file reads
Yogeta WP Cloud through 1.0 passes a caller-controlled path from a public endpoint to a file-read operation without authorization or path validation. An unauthenticated attacker can download arbitrary server files, including configuration files containing credentials. The authoritative export does not name the endpoint, path parameter, or file-read function.
|
See mitigation notes |
CVE8.6
NVDPending
|