File Upload Vulnerability in Webinfos WordPress Plugin by Webinfos
CVE-2026-12872
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-12872?
The Webinfos WordPress plugin version 1.2 lacks proper validation mechanisms for uploaded files, allowing unauthenticated attackers to upload arbitrary files, including potentially malicious PHP scripts. This presents a significant security risk as it enables remote code execution in directories accessible to the web server, facilitating unauthorized access and control over the affected systems.
Affected Version(s)
Webinfos 0 <= 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.