What is CVE-2026-12872?
This is a critical vulnerability in the Webinfos WordPress plugin (up to version 1.2) where missing file type, name validation, and lack of authentication, capability, or nonce checks allow unauthenticated attackers to upload arbitrary files, including PHP, leading to Remote Code Execution (RCE). Affected users should immediately update or remove the plugin and scan servers for malicious uploads.
Azərbaycanca: Bu, Webinfos WordPress plaginində (versiya 1.2 daxil olmaqla) yükləmə fayllarının tipi, adı yoxlanılmadığı və heç bir autentifikasiya, səlahiyyət və ya nonce tələb olunmadığı üçün autentifikasiya olunmamış hücumçulara veb-serverə PHP daxil olmaqla ixtiyari fayl yükləməyə imkan verən kritik boşluqdur. Bu, uzaqdan kod icrasına (RCE) gətirib çıxara bilər. Təsirə məruz qalmış istifadəçilər plaqini dərhal yeniləməli və ya silməli, həmçinin yüklənmiş fayllar üçün serveri yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Why is CVE-2026-12872 considered critical?
This vulnerability is critical because it allows arbitrary file uploads without authentication, capability checks, or nonce, enabling an attacker to upload PHP files and achieve Remote Code Execution (RCE).
What should users affected by CVE-2026-12872 do?
Affected users should immediately update or remove the Webinfos WordPress plugin and scan their servers for malicious uploaded files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.