Arbitrary File Upload Vulnerability in Rara One Click Demo Import Plugin for WordPress
CVE-2026-26212

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2026

What is CVE-2026-26212?

The Rara One Click Demo Import plugin for WordPress prior to version 1.3.5 features an arbitrary file upload vulnerability. This issue allows authenticated users with Administrator rights to bypass the WordPress core's file type validation checks. By supplying a deceptive value to the wp_handle_upload() function, attackers can upload malicious PHP scripts into the uploads directory. These scripts remain executable via HTTP, enabling remote code execution within the web server's process. Moreover, the uploaded files persist on the server even after deactivating the plugin, avoiding standard media library checks and integrity validations.

Affected Version(s)

Rara One Click Demo Import 0 < 1.3.5

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rinesa Krasniqi
VulnCheck
.