CRITICAL 9.8 CVE-2026-84171 Published 12 Sept 2026

Piclect WordPress Plugin Arbitrary File Upload

Worried this affects one of your servers?

The piclect WordPress plugin, version 1.0, has a critical vulnerability in its image upload functionality.

WP images upload on this plugin does not validate the name or type of uploaded files, allowing unauthenticated attackers to upload arbitrary files to a publicly accessible directory.

This vulnerability can be exploited to execute arbitrary code on the server.

Reference: CVE-2026-84171 on NVD

← Back to Security News