Unrated severityNVD Advisory· Published Aug 3, 2026
Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
CVE-2026-12872
Description
The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/40e78256-6a84-44fc-b35b-26c21317691e/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.