PT-2026-99395 · Joomla · Up Plugin
CVE-2026-97160
·
Published
2026-09-26
·
Updated
2026-09-29
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
UP plugin versions 5.0.0 through 5.2.0
UP plugin versions 6.0.0 through 6.0.29
UP plugin versions prior to 6.1.0
Description
An authenticated, privileged PHP command injection exists in the UP plugin extension. Additionally, an unauthenticated flaw allows the reading of the Joomla site's
configuration.php file.Recommendations
Update UP plugin versions 5.0.0 through 5.2.0 to version 6.1.0.
Update UP plugin versions 6.0.0 through 6.0.29 to version 6.1.0.
Update all versions prior to 6.1.0 to version 6.1.0.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Up Plugin