What is CVE-2026-15786?
This CVE describes a Directory Traversal vulnerability in the "WP Encryption" WordPress plugin up to version 7.8.6.6 via the 'imploded' parameter. It allows authenticated attackers, likely with administrative access, to read sensitive files on the server. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu CVE, WordPress-in "WP Encryption" plaqininin 7.8.6.6 versiyasına qədər olan bütün versiyalarında 'imploded' parametri vasitəsilə Directory Traversal zəifliyini təsvir edir. Autentifikasiya olunmuş administrator səviyyəli hücumçulara serverdəki həssas faylları oxumağa imkan verə bilər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the 'WP Encryption' plugin are affected by CVE-2026-15786?
This vulnerability affects all versions of the 'WP Encryption' plugin up to version 7.8.6.6.
What level of access does an attacker need to exploit CVE-2026-15786?
The attacker must be authenticated with administrative-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.