The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-12872
Mitre link : CVE-2026-12872
CVE.ORG link : CVE-2026-12872
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
