Unauthenticated File Upload Vulnerability in Type Hub by WordPress
CVE-2026-66665
10CRITICAL
What is CVE-2026-66665?
The Type Hub plugin for WordPress, in versions up to 2.0.6, is susceptible to an unauthenticated arbitrary file upload vulnerability. This flaw allows attackers to upload malicious files without authentication, potentially leading to unauthorized access or execution of harmful code on the server. It is crucial for users of this plugin to update to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Type Hub <= 2.0.6