Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
WordPress Plugin Allows Malicious File Uploads
CVE-2026-26301
Summary
A WordPress plugin that allows users to upload files has a weakness that could allow attackers to upload malicious files, potentially leading to data theft or website compromise. This affects plugins using this functionality and poses a risk to sensitive data and website integrity. To mitigate this, update the plugin to the latest version or consider replacing it with a secure alternative.
Original title
Rejected reason: Not used
Original description
Rejected reason: Not used
Published: 14 Feb 2026 · Updated: 10 Mar 2026 · First seen: 6 Mar 2026