PT-2026-57395 · WordPress · Swiss Toolkit For Wp

·

CVE-2026-2354

·

Published

2026-07-11

·

Updated

2026-07-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Swiss Toolkit For WP versions prior to 1.4.7
Description An arbitrary file upload issue exists due to flawed file type validation in the upload extension files() function. The function uses strpos() to check if a filename contains a configured extension string instead of verifying the actual file extension. Authenticated attackers with Author-level access or higher can upload arbitrary files, such as PHP scripts, to the server, potentially leading to remote code execution. This is possible when the Enhanced Multi-Format Image Support feature is enabled with at least one allowed extension, such as avif.
Recommendations Update Swiss Toolkit For WP to version 1.4.7 or later. As a temporary mitigation, disable the Enhanced Multi-Format Image Support feature.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2354

Affected Products

Swiss Toolkit For Wp