Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin 'Mini' Unauthenticated File Upload

MINI-6prq-xm36-fxgj
Summary

A WordPress plugin called 'Mini' allows attackers to upload files without needing a password. This could allow hackers to add malicious code to your website. You should update the plugin to the latest version or remove it if possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
Ecosystem VendorProductAffected versions
MinimOS – gitlab-exporter-18.3 All versions
Original title
MINI-6prq-xm36-fxgj
Published: 20 Jun 2026 · Updated: 20 Jun 2026 · First seen: 20 Jun 2026