Unauthenticated SQL Injection in WordPress File Upload Plugin by WordPress
CVE-2026-62071

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-62071?

A security flaw exists in the WordPress File Upload Plugin, allowing unauthenticated attackers to execute SQL injection attacks. This vulnerability affects versions up to 5.1.10, enabling potential access to sensitive database information, thereby compromising site integrity. Implementing the latest updates or patches is crucial to safeguard your WordPress site from such vulnerabilities.

Affected Version(s)

WordPress File Upload <= 5.1.10

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andy Urlep | Patchstack Bug Bounty Program
.