What is CVE-2026-14553?
The vulnerability stems from improper file upload validation in the zportals WordPress plugin, allowing any authenticated user to upload arbitrary PHP files due to reliance on client-supplied content type and preserved file extensions. This can lead to remote code execution. Users should update the plugin to version 6.3.4 or higher.
Azərbaycanca: Bu boşluq zportals WordPress plaginində fayl yükləmə yoxlamasının düzgün aparılmaması ilə bağlıdır. Zərərli PHP faylların yüklənməsinə imkan verir, bu da autentifikasiya olunmuş istənilən istifadəçiyə uzaqdan kod icrasına nail olmaq imkanı yaradır. Plagini ən az 6.3.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Is authentication required to exploit CVE-2026-14553?
Yes, this vulnerability allows any authenticated user to upload malicious PHP files.
Which version of zportals plugin should be updated to protect against CVE-2026-14553?
Users are recommended to update the plugin to version 6.3.4 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.