The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-80494 represents a critical vulnerability in the Yogeta WP Cloud WordPress plugin where insufficient input validation combines with missing authorization controls to enable arbitrary file disclosure. The vulnerability exists in a public endpoint that accepts user-supplied file paths without sanitization, then directly passes them to file-read operations. This allows unauthenticated attackers to traverse the server filesystem and exfiltrate sensitive files—including configuration files with database credentials, API keys, and other secrets—without requiring any valid user account. Organizations running WordPress sites with this plugin installed face immediate risk of credential compromise and lateral movement within their infrastructure.
While this CVE lacks direct MITRE ATT&CK mapping, Casky's Claude-powered analysis engine would detect the attack patterns underlying this vulnerability across multiple security skill domains. Practitioners using Casky would observe detection signals related to T1083 (File and Directory Discovery), T1552 (Unsecured Credentials), and T1005 (Data from Local System) as the vulnerability enables reconnaissance and sensitive data collection. The extended reasoning capabilities would correlate the suspicious access pattern—unauthenticated requests to unusual file paths combined with successful file reads—against authorization and input validation skill assessments, flagging the absence of proper path canonicalization, allowlist validation, and authentication checks. Security teams would see findings highlighting the need for endpoint authentication enforcement, input sanitization patterns, and file access control implementations that prevent directory traversal attacks.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-80494. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation