The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-12 06:16
Updated : 2026-09-14 21:10
NVD link : CVE-2026-81090
Mitre link : CVE-2026-81090
CVE.ORG link : CVE-2026-81090
JSON object : View
Products Affected
No product.
