CVE-2026-12872

CRITICAL

Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload

Title source: cna
STIX 2.1

Description

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/40e78256-6a84-44fc-b35b-26c21317691e/

Scores

CVSS v3 9.8
EPSS 0.0069
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
None/Webinfos < 1.2
Published Aug 03, 2026
Tracked Since Aug 03, 2026