Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-32559: UltimateAI plugin lets attackers upload files

CVE-2026-32559 · published 1 month ago
Summary

The UltimateAI plugin for WordPress (versions up to 3.1.0) lets a low‑privilege user place any file on the server. This could let an attacker add malicious code, potentially taking control of the website. Update the plugin to a newer version or remove it if you do not need the functionality.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tophive ultimateai <= 3.1.0
Original advisory text
WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published24 Aug 2026
Updated27 Sep 2026
First seen24 Aug 2026
Sources
CVE-2026-32559 · MITRE
Track software like this
Free during beta