CRITICAL
9.3 CVE-2026-62071 Published 1 Oct 2026
WordPress File Upload Plugin SQL Injection Vulnerability
Worried this affects your website?
WordPress File Upload versions 5.1.10 and earlier are affected by an unauthenticated SQL injection vulnerability.
This flaw can be exploited without authentication, putting site databases at risk.
Reference: CVE-2026-62071 on NVD
← Back to Security News