The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The shared-files-pro WordPress plugin versions before 1.7.70 contain a critical path traversal vulnerability in featured image creation functionality. By failing to validate file paths, the plugin allows unauthenticated attackers to read arbitrary files from the server and expose them publicly. This vulnerability affects any WordPress installation using the vulnerable plugin version, regardless of access level. The impact is severe: sensitive configuration files, database credentials, source code, and other confidential data become accessible to any threat actor who discovers the plugin's presence.
While this CVE doesn't currently map to specific MITRE ATT&CK techniques in public databases, Casky's security skills leverage Claude's extended reasoning to identify the attack patterns within this vulnerability. Practitioners using Casky would recognize this as a pattern associated with T1083 (File and Directory Discovery) and T1005 (Data from Local System) techniques—adversaries systematically probing for and exfiltrating files. The zero authentication requirement also maps to initial access patterns. Although Casky currently shows zero direct skill matches for this specific CVE, the platform's AI-driven analysis helps practitioners understand that path traversal vulnerabilities like this one represent a foundational attack pattern worth monitoring across their WordPress ecosystem, enabling proactive detection of similar validation failures before they're exploited.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19084. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation