PT-2026-99396 · Unknown · Up Plugin Extension
CVE-2026-97161
·
Published
2026-09-26
·
Updated
2026-09-29
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
UP plugin extension versions 5.0.0 through 5.2.0
UP plugin extension versions 6.0.0 through 6.0.29
Description
Various path traversal and file access vectors exist within the UP plugin extension. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference files with dot-dot-slash (../) sequences.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Up Plugin Extension