Arbitrary File Upload Vulnerability in UltimateAI Plugin by WordPress
CVE-2026-32559

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-32559?

The UltimateAI Plugin for WordPress is susceptible to an arbitrary file upload vulnerability, allowing authenticated users with the Subscriber role to upload files of their choice. This vulnerability exists in versions of the plugin up to and including 3.1.0. Attackers may exploit this flaw to upload potentially malicious files, leading to unauthorized access and compromise of the web server. It is crucial for users of this plugin to ensure they are using the latest version to mitigate risks.

Affected Version(s)

UltimateAI <= 3.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jamaal ahmed | Patchstack Bug Bounty Program
.