CPE
An authenticated administrator can exploit CVE-2026-26212 in the Rara One Click Demo Import plugin to achieve remote code execution by bypassing file type validation during the upload process.