CVE-2026-81090

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 06:16

Updated : 2026-09-14 21:10


NVD link : CVE-2026-81090

Mitre link : CVE-2026-81090

CVE.ORG link : CVE-2026-81090


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-434

Unrestricted Upload of File with Dangerous Type