PT-2026-90566 · Undefined · Undefined
CVE-2026-81090
·
Published
2026-09-12
·
Updated
2026-09-17
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gpx2Graphics WordPress plugin versions prior to 0.4
Description
The plugin fails to perform a Cross-Site Request Forgery (CSRF) check during file upload operations and does not validate the type of uploaded files. This allows an attacker to trick a logged-in administrator into uploading arbitrary files, such as PHP scripts, which can lead to Remote Code Execution (RCE). CSRF is a technique where an attacker forces a victim to execute unwanted actions on a web application in which they are currently authenticated.
Recommendations
Update the Gpx2Graphics WordPress plugin to version 0.4 or later.
Exploit
Fix
RCE
CSRF
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined