File upload

Authentication Bypass in UpdraftPlus

UpdraftPlus is one of the most popular WordPress backup plugins, with over 3 million active installations. In versions before 1.26.5, it contained a critical authentication bypass vulnerability that allowed unauthenticated attackers to restore arbitrary backups to a site.

13 June 2026

Read more

Kadence Blocks: Missing Authorization Allows Arbitrary File Uploads

This is a bit of an older one, but it's still important to highlight. The popular Kadence Blocks plugin had a missing authorisation vulnerability in versions up to 3.6.3. This allowed authenticated users with the Contributor role to upload arbitrary files to the Media Library.

11 May 2026

Read more

Unauthenticated RCE in File Uploader for WooCommerce

File Uploader for WooCommerce up to 1.0.3 exposes an unauthenticated REST endpoint that pulls an attacker-controlled file from Uploadcare into the uploads directory with any extension. Full pre-auth RCE (CVE-2025-13329, CVSS 9.8).

9 April 2026

Read more