Tag
Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)
2 rules 4 TTPs 1 CVEA critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.
Easy Digital Downloads Plugin Arbitrary File Upload Leads to RCE (CVE-2026-12476)
1 rule 3 TTPs 1 CVEThe Easy Digital Downloads plugin for WordPress versions up to and including 3.6.9 is vulnerable to Arbitrary File Upload (CVE-2026-12476) due to insufficient file type validation, allowing authenticated attackers with Shop Manager-level access or higher to upload arbitrary files which can lead to remote code execution.
WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 IOCThe WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.
GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)
1 rule 2 TTPs 1 CVEAn arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.
MapSVG WordPress Plugin Vulnerability Allows Arbitrary File Uploads (CVE-2026-1771)
1 rule 3 TTPs 1 CVEAn authenticated attacker with Administrator-level access can exploit CVE-2026-1771 in the MapSVG WordPress plugin, affecting versions up to 8.14.0, due to missing file type validation, enabling arbitrary file uploads and potentially leading to remote code execution on the server.
CVE-2026-13430: WordPress Post Export Import with Media Plugin Arbitrary File Upload Leading to RCE
1 rule 2 TTPs 1 CVEA high-severity arbitrary file upload vulnerability, CVE-2026-13430, exists in all versions up to 1.13.1 of the Post Export Import with Media plugin for WordPress, allowing authenticated administrators to upload executable web shells via a trailing-dot filename bypass, leading to remote code execution.
WordPress Super Forms Plugin Arbitrary File Upload (CVE-2026-14894)
1 rule 2 TTPs 1 CVE 1 IOCAn unauthenticated arbitrary file upload vulnerability (CVE-2026-14894) exists in the Super Forms - Drag & Drop Form Builder plugin for WordPress, affecting all versions up to and including 6.3.313, allowing unauthenticated attackers to upload executable files via the `submit_form` AJAX handler, leading to remote code execution after trivial nonce bypass.
CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE
2 TTPs 1 CVEThe Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.
Joomla Page Builder CK Arbitrary File Upload (EDB-52626)
3 TTPsA public exploit has been released for an arbitrary file upload vulnerability in Joomla Page Builder CK version 3.5.10, which allows an unauthenticated attacker to upload malicious files to the server, potentially leading to remote code execution and full system compromise.
CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE
3 TTPs 1 CVEAuthenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.
DreamMaker Arbitrary File Upload Vulnerability (CVE-2026-10072)
2 rules 2 TTPs 1 CVEDreamMaker by Interinfo is vulnerable to arbitrary file upload, allowing privileged remote attackers to upload and execute web shell backdoors, enabling arbitrary code execution on the server.
CVE-2026-9227: GutenBee WordPress Plugin Arbitrary File Upload
2 rules 1 CVEThe GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level access to achieve remote code execution by uploading executable files with double extensions.
CVE-2026-6960: BookingPress Pro Plugin Arbitrary File Upload Leading to Potential RCE
2 rules 3 TTPs 1 CVEThe BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in versions up to 5.6, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution if a signature custom field is added to the booking form.
Piotnet Forms WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-4883)
2 rules 1 TTP 1 CVEThe Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution.
CVE-2026-4885: Piotnet Addons for Elementor Pro WordPress Plugin Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe Piotnet Addons for Elementor Pro plugin for WordPress, versions up to 7.1.70, is vulnerable to unauthenticated arbitrary file upload due to insufficient file type validation in the 'pafe_ajax_form_builder' function, potentially leading to remote code execution.
CVE-2026-6271: WordPress Career Section Plugin Arbitrary File Upload Vulnerability
2 rules 1 CVEThe Career Section plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.7 due to missing file type validation in the CV upload handler, potentially leading to remote code execution.
Sunnet CTMS/CPAS Arbitrary File Upload Vulnerability (CVE-2026-7490)
2 rules 3 TTPs 1 CVEA privileged remote attacker can exploit CVE-2026-7490 in Sunnet CTMS and CPAS to upload and execute web shell backdoors, leading to arbitrary code execution on the server.
Betheme WordPress Theme Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe Betheme theme for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level privileges or higher to upload arbitrary files, including PHP, leading to remote code execution.
livewire-markdown-editor Arbitrary File Upload Vulnerability
2 rules 1 TTPThe livewire-markdown-editor versions before v1.3 contain an arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler, allowing authenticated users to upload any file type, potentially leading to stored XSS, phishing, malware distribution, and markdown injection.