PT-2026-90566 · Undefined · Undefined

CVE-2026-81090

·

Published

2026-09-12

·

Updated

2026-09-17

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gpx2Graphics WordPress plugin versions prior to 0.4
Description The plugin fails to perform a Cross-Site Request Forgery (CSRF) check during file upload operations and does not validate the type of uploaded files. This allows an attacker to trick a logged-in administrator into uploading arbitrary files, such as PHP scripts, which can lead to Remote Code Execution (RCE). CSRF is a technique where an attacker forces a victim to execute unwanted actions on a web application in which they are currently authenticated.
Recommendations Update the Gpx2Graphics WordPress plugin to version 0.4 or later.

Exploit

Fix

RCE

CSRF

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81090

Affected Products

Undefined