PT-2026-69355 · WordPress · Squeeze

·

CVE-2026-16985

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Squeeze WordPress plugin versions prior to 1.7.12
Description Insufficient validation of file types or extensions during attachment-update actions allows users with the upload files capability, such as those with Author privileges and above, to upload executable PHP files into the uploads directory. This flaw can lead to remote code execution, which is the ability of an attacker to execute arbitrary commands on the server.
Recommendations Update Squeeze WordPress plugin to version 1.7.12 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16985

Affected Products

Squeeze