Missing Authorization in Canto Plugin for WordPress
CVE-2026-3335
What is CVE-2026-3335?
The Canto plugin for WordPress is susceptible to a Missing Authorization flaw that allows unauthenticated users to upload files to the server. This vulnerability arises from a lack of adequate authentication and authorization controls in the copy-media.php file. Specifically, the permissive design permits direct access to certain endpoints, letting attackers manipulate user-supplied parameters to initiate file uploads from arbitrary external servers. Since the system does not verify the authenticity of requests, attackers can exploit this weakness, leading to potential malicious file uploads in the WordPress uploads directory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Canto * <= 3.1.1