Arbitrary File Upload Vulnerability in Rara One Click Demo Import Plugin for WordPress
CVE-2026-26212
8.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-26212?
The Rara One Click Demo Import plugin for WordPress prior to version 1.3.5 features an arbitrary file upload vulnerability. This issue allows authenticated users with Administrator rights to bypass the WordPress core's file type validation checks. By supplying a deceptive value to the wp_handle_upload() function, attackers can upload malicious PHP scripts into the uploads directory. These scripts remain executable via HTTP, enabling remote code execution within the web server's process. Moreover, the uploaded files persist on the server even after deactivating the plugin, avoiding standard media library checks and integrity validations.
Affected Version(s)
Rara One Click Demo Import 0 < 1.3.5