Arbitrary File Read Vulnerability in UnderConstructionPage PRO for WordPress
CVE-2026-11426

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 July 2026

What is CVE-2026-11426?

The UnderConstructionPage PRO plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access and higher to exploit arbitrary file read conditions. This occurs due to improper handling of the template_thumbnail parameter, which permits the input of local file paths. Consequently, sensitive information may be exposed as these files are copied into publicly accessible uploads directories. All versions up to 5.76 are affected, potentially compromising site integrity and data confidentiality.

Affected Version(s)

Under Construction Page (Pro) 0 <= 5.76

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Duc (duc193)
.