Skip to content
Threat Feed

Tag

Arbitrary File Upload

19 briefs RSS
critical advisory

Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)

A critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.

Extra Checkout Options wordpress plugin arbitrary-file-upload rce web-application
2r 4t 1c
high advisory

Easy Digital Downloads Plugin Arbitrary File Upload Leads to RCE (CVE-2026-12476)

The Easy Digital Downloads plugin for WordPress versions up to and including 3.6.9 is vulnerable to Arbitrary File Upload (CVE-2026-12476) due to insufficient file type validation, allowing authenticated attackers with Shop Manager-level access or higher to upload arbitrary files which can lead to remote code execution.

Easy Digital Downloads plugin web arbitrary-file-upload rce wordpress plugin
1r 3t 1c
high advisory

WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE

The WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.

WPForms Pro plugin for WordPress <= 1.10.1.1 +1 wordpress rce arbitrary-file-upload web-vulnerability
1r 2t 1i updated
critical advisory

GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)

An arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.

GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Vid... <= 1.12.2 wordpress arbitrary-file-upload remote-code-execution web-exploitation
1r 2t 1c
high advisory

MapSVG WordPress Plugin Vulnerability Allows Arbitrary File Uploads (CVE-2026-1771)

An authenticated attacker with Administrator-level access can exploit CVE-2026-1771 in the MapSVG WordPress plugin, affecting versions up to 8.14.0, due to missing file type validation, enabling arbitrary file uploads and potentially leading to remote code execution on the server.

MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 wordpress plugin arbitrary-file-upload rce web-application
1r 3t 1c
high advisory

CVE-2026-13430: WordPress Post Export Import with Media Plugin Arbitrary File Upload Leading to RCE

A high-severity arbitrary file upload vulnerability, CVE-2026-13430, exists in all versions up to 1.13.1 of the Post Export Import with Media plugin for WordPress, allowing authenticated administrators to upload executable web shells via a trailing-dot filename bypass, leading to remote code execution.

Post Export Import with Media plugin web-vulnerability wordpress arbitrary-file-upload rce
1r 2t 1c
critical advisory

WordPress Super Forms Plugin Arbitrary File Upload (CVE-2026-14894)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-14894) exists in the Super Forms - Drag & Drop Form Builder plugin for WordPress, affecting all versions up to and including 6.3.313, allowing unauthenticated attackers to upload executable files via the `submit_form` AJAX handler, leading to remote code execution after trivial nonce bypass.

PoC Super Forms – Drag & Drop Form Builder <= 6.3.313 +1 wordpress plugin arbitrary-file-upload rce web-exploit
1r 2t 1c 1i updated
critical advisory

CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE

The Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.

Blocksy Companion plugin +3 web vulnerability arbitrary-file-upload wordpress
2t 1c
high advisory

Joomla Page Builder CK Arbitrary File Upload (EDB-52626)

A public exploit has been released for an arbitrary file upload vulnerability in Joomla Page Builder CK version 3.5.10, which allows an unauthenticated attacker to upload malicious files to the server, potentially leading to remote code execution and full system compromise.

Joomla Page Builder CK 3.5.10 webapps arbitrary-file-upload joomla remote-code-execution
3t
high advisory

CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE

Authenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.

WHMCS Bridge <= 6.9 wordpress arbitrary-file-upload remote-code-execution web-vulnerability plugin-vulnerability
3t 1c
high advisory

DreamMaker Arbitrary File Upload Vulnerability (CVE-2026-10072)

DreamMaker by Interinfo is vulnerable to arbitrary file upload, allowing privileged remote attackers to upload and execute web shell backdoors, enabling arbitrary code execution on the server.

DreamMaker arbitrary-file-upload web-shell code-execution
2r 2t 1c
high advisory

CVE-2026-9227: GutenBee WordPress Plugin Arbitrary File Upload

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level access to achieve remote code execution by uploading executable files with double extensions.

GutenBee – Gutenberg Blocks plugin <= 2.20.1 arbitrary-file-upload remote-code-execution wordpress
2r 1c
critical advisory

CVE-2026-6960: BookingPress Pro Plugin Arbitrary File Upload Leading to Potential RCE

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in versions up to 5.6, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution if a signature custom field is added to the booking form.

BookingPress Pro plugin <= 5.6 wordpress arbitrary-file-upload rce plugin CVE-2026-6960 webserver
2r 3t 1c
critical advisory

Piotnet Forms WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-4883)

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution.

Piotnet Forms plugin <= 2.1.40 arbitrary-file-upload wordpress plugin CVE-2026-4883
2r 1t 1c
critical threat

CVE-2026-4885: Piotnet Addons for Elementor Pro WordPress Plugin Arbitrary File Upload Vulnerability

The Piotnet Addons for Elementor Pro plugin for WordPress, versions up to 7.1.70, is vulnerable to unauthenticated arbitrary file upload due to insufficient file type validation in the 'pafe_ajax_form_builder' function, potentially leading to remote code execution.

Piotnet Addons for Elementor Pro <= 7.1.70 arbitrary-file-upload rce wordpress plugin
2r 1t 1c
critical threat

CVE-2026-6271: WordPress Career Section Plugin Arbitrary File Upload Vulnerability

The Career Section plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.7 due to missing file type validation in the CV upload handler, potentially leading to remote code execution.

Career Section plugin arbitrary file upload remote code execution wordpress plugin
2r 1c
high advisory

Sunnet CTMS/CPAS Arbitrary File Upload Vulnerability (CVE-2026-7490)

A privileged remote attacker can exploit CVE-2026-7490 in Sunnet CTMS and CPAS to upload and execute web shell backdoors, leading to arbitrary code execution on the server.

CTMS +1 arbitrary-file-upload web-shell code-execution
2r 3t 1c
critical advisory

Betheme WordPress Theme Arbitrary File Upload Vulnerability

The Betheme theme for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level privileges or higher to upload arbitrary files, including PHP, leading to remote code execution.

Betheme theme arbitrary-file-upload rce wordpress betheme
2r 1t 1c
high advisory

livewire-markdown-editor Arbitrary File Upload Vulnerability

The livewire-markdown-editor versions before v1.3 contain an arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler, allowing authenticated users to upload any file type, potentially leading to stored XSS, phishing, malware distribution, and markdown injection.

mckenziearts/livewire-markdown-editor +3 arbitrary-file-upload stored-xss vulnerability
2r 1t