Unrated severityNVD Advisory· Published Sep 12, 2026
CVE-2026-81090
CVE-2026-81090
Description
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=0.3+ 1 more
- (no CPE)range: <=0.3
- (no CPE)range: <=0.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.