cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-7848,https://securityvulnerability.io/vulnerability/CVE-2024-7848,File Sharing Plugin Vulnerable to Insecure Direct Object Reference,"The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to gain access to other user's private files.",Wordpress,User Private Files – WordPress File Sharing Plugin,6.5,MEDIUM,0.0004900000058114529,false,,false,false,false,,,false,false,,2024-08-22T10:58:41.183Z,0