
Secure Client Portal and Private File Sharing Plugin – User Private Files Security & Risk Analysis
wordpress.org/plugins/user-private-filesWordPress secure client portal plugin with file sharing and document manager. Upload, manage and share documents with users safely.
Is Secure Client Portal and Private File Sharing Plugin – User Private Files Safe to Use in 2026?
Generally Safe
Score 92/100Secure Client Portal and Private File Sharing Plugin – User Private Files has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The user-private-files v2.1.6 plugin presents a mixed security posture. On the positive side, the plugin demonstrates good practices in its use of prepared statements for SQL queries and has a substantial number of nonce and capability checks, indicating an effort to secure its entry points. The static analysis shows no critical or high severity taint flows, and all identified entry points have some form of authorization check.
However, significant concerns arise from its vulnerability history. The plugin has a history of 7 known CVEs, with a recent one in 2025. While none are currently unpatched, the prevalence of medium severity vulnerabilities, including Authorization Bypass, Cross-Site Scripting (XSS), Missing Authorization, Exposure of Sensitive Information, and Unrestricted Uploads, points to recurring and potentially systemic security weaknesses. The fact that 20% of output is not properly escaped, despite a large number of output operations, is a significant concern for potential XSS vulnerabilities. The presence of unsanitized paths in taint analysis, even without critical severity, warrants attention.
In conclusion, while the plugin has implemented some essential security mechanisms, its past and the presence of output escaping issues suggest a need for ongoing scrutiny and potential refactoring. The historical trend of diverse and repeated vulnerability types indicates a need for a thorough security review to address underlying coding practices.
Key Concerns
- Output escaping issues (20% unescaped)
- Vulnerability history (6 medium CVEs)
- Flows with unsanitized paths
Secure Client Portal and Private File Sharing Plugin – User Private Files Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter
User Private Files – File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
User Private Files <= 2.1.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access
User Private Files < 2.0.5 - Insecure Direct Object Reference
WordPress File Sharing Plugin <= 2.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting
Frontend File Manager & Sharing – User Private Files <= 1.1.1 - Missing Authorization
Frontend File Manager & Sharing – User Private Files <= 1.1.0 - Sensitive Information Disclosure
Frontend File Manager & Sharing – User Private Files <= 1.1.2 - Subscriber+ Arbitrary File Upload
Secure Client Portal and Private File Sharing Plugin – User Private Files Release Timeline
Secure Client Portal and Private File Sharing Plugin – User Private Files Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Secure Client Portal and Private File Sharing Plugin – User Private Files Attack Surface
AJAX Handlers 54
Shortcodes 3
WordPress Hooks 16
Maintenance & Trust
Secure Client Portal and Private File Sharing Plugin – User Private Files Maintenance & Trust
Maintenance Signals
Community Trust
Secure Client Portal and Private File Sharing Plugin – User Private Files Alternatives
Filevue
filevue
A private WordPress client portal, auto-installed on activation. Secure logins, folders, file sharing, staff access, activity tracking, and branding.
Document Library Lite
document-library-lite
Create a WordPress document library to manage, search and download files.
Filr – Secure document library
filr-protection
Easily Create a Secure Document Library with Filr
FileDeck – Document Library & Download Manager
filedeck
Searchable, sortable document library: table, grid, or folder layouts with instant search, filters, download tracking, and a Gutenberg block.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Secure Client Portal and Private File Sharing Plugin – User Private Files Developer Profile
8 plugins · 5K total installs
How We Detect Secure Client Portal and Private File Sharing Plugin – User Private Files
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-private-files/css/admin/admin_free.css/wp-content/plugins/user-private-files/js/admin/admin-upf_free.js/wp-content/plugins/user-private-files/css/admin/chosen.min.css/wp-content/plugins/user-private-files/js/lib/chosen.jquery.min.js/wp-content/plugins/user-private-files/css/fa.min.css/wp-content/plugins/user-private-files/css/classic-style.css/wp-content/plugins/user-private-files/js/classic-main.js/wp-content/plugins/user-private-files/css/style.css+4 morejs/admin/admin-upf_free.jsjs/lib/chosen.jquery.min.jsjs/classic-main.jsjs/waitforimages.min.jsjs/file.jsjs/folder.js+1 moreuser-private-files/css/admin/admin_free.css?ver=user-private-files/js/admin/admin-upf_free.js?ver=user-private-files/css/admin/chosen.min.css?ver=user-private-files/js/lib/chosen.jquery.min.js?ver=user-private-files/css/fa.min.css?ver=user-private-files/css/classic-style.css?ver=user-private-files/js/classic-main.js?ver=user-private-files/css/style.css?ver=user-private-files/js/waitforimages.min.js?ver=user-private-files/js/file.js?ver=user-private-files/js/folder.js?ver=user-private-files/js/bulk-action.js?ver=HTML / DOM Fingerprints
upf-docsupf-file-manager<!-- User Private Files --><!-- END User Private Files -->data-upf-iddata-upf-typeajax_upf_classic_objajax_upf_objajax_upvf_frnt_objajax_upvf_bulk_objupvf_template_loader/wp-json/upf/v1/get-folders/wp-json/upf/v1/get-files/wp-json/upf/v1/upload-file/wp-json/upf/v1/delete-file/wp-json/upf/v1/create-folder/wp-json/upf/v1/delete-folder/wp-json/upf/v1/rename-file/wp-json/upf/v1/rename-folder[user_private_files][upf_folders][upf_files]