What is CVE-2026-16548?
An unauthenticated arbitrary file upload vulnerability was discovered in the Chat Widget WordPress plugin prior to version 1.8.2. Attackers can upload files without proper type, extension, content, or size validation through the public response endpoint, posing a remote code execution risk — users should update to the latest version immediately.
Azərbaycanca: WordPress üçün Chat Widget plaginində (1.8.2-dən əvvəlki versiyalarda) autentifikasiya olunmamış fayl yükləmə zəifliyi aşkar edilib. Bu, təcavüzkara açıq response endpoint vasitəsilə fayl tipi, məzmunu və ölçüsü yoxlanılmadan serverə fayl yerləşdirməyə imkan verir — plaginin son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which versions of the Chat Widget plugin are affected by CVE-2026-16548?
All versions prior to 1.8.2 are affected.
What does the CVE-2026-16548 vulnerability allow an unauthenticated user to do?
It allows uploading files without type, extension, content, or size validation through the public response endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.