Arbitrary File Read Vulnerability in UnderConstructionPage PRO for WordPress
CVE-2026-11426
6.5MEDIUM
What is CVE-2026-11426?
The UnderConstructionPage PRO plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access and higher to exploit arbitrary file read conditions. This occurs due to improper handling of the template_thumbnail parameter, which permits the input of local file paths. Consequently, sensitive information may be exposed as these files are copied into publicly accessible uploads directories. All versions up to 5.76 are affected, potentially compromising site integrity and data confidentiality.
Affected Version(s)
Under Construction Page (Pro) 0 <= 5.76