Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin Allows Malicious File Uploads

CVE-2026-26301
Summary

A WordPress plugin that allows users to upload files has a weakness that could allow attackers to upload malicious files, potentially leading to data theft or website compromise. This affects plugins using this functionality and poses a risk to sensitive data and website integrity. To mitigate this, update the plugin to the latest version or consider replacing it with a secure alternative.

Original title
Rejected reason: Not used
Original description
Rejected reason: Not used
Published: 14 Feb 2026 · Updated: 10 Mar 2026 · First seen: 6 Mar 2026