A Local File Inclusion vulnerability has been identified in the WordPress Dropbox Folder Share Plugin. This vulnerability could allow a malicious actor to include local files of the target website and show its output onto the screen. Files that store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration.

This vulnerability was discovered and responsibly reported by Marco Wotschka.

The vulnerability is a Local File Inclusion vulnerability that occurs in the dropbox-folder-share.php file. The vulnerability allows an attacker to exploit a flaw in the way that the plugin handles user input to include local files of the website.

The vendor has not yet released a patched version of the plugin. Users are advised to uninstall the plugin until a patched version is released.


The vulnerability has a CVSS 3.1 score of 9.8, which is considered to be critical. This means that the vulnerability is very likely to be exploited and could have a severe impact on the affected system.

Affected Versions:

The vulnerability affects all versions of the Dropbox Folder Share Plugin.


An attacker who successfully exploits this vulnerability could:

  • Include local files of the target website and show its output onto the screen.
  • Access sensitive files on the website, such as database credentials, configuration files, and user data.
  • Execute arbitrary PHP code on the website.
  • Take full control of the website.


Users of the Dropbox Folder Share Plugin are strongly advised to take the following action for the website’s defenses:

  • Disable the Plugin: In the absence of a patched version, consider disabling the Dropbox Folder Share Plugin until a security fix is provided. This can help mitigate the potential risks associated with the vulnerability.
  • Enhance Security Measures: Strengthen the website’s security measures by implementing robust authentication protocols, access controls, and regular security audits. This proactive approach is essential to thwart potential exploitation attempts.