What is CVE-2026-16618?
This vulnerability affects the Improve SEO WordPress plugin up to version 2.0.11, where improper file upload validation only checks the content type but allows attacker-supplied extensions, leading to unauthenticated malicious PHP file uploads in a publicly accessible directory. Remote Code Execution can be achieved, so immediate update to the latest patched version is required.
Azərbaycanca: Bu boşluq, Improve SEO WordPress plagininin 2.0.11-ə qədər versiyalarında fayl yükləmə validasiyasının yalnış aparılması ilə bağlıdır. Doğrulama yalnız fayl məzmun növünə əsaslanır, lakin faylın təhlükəli uzantısı (məsələn, PHP) dəyişdirilərək ictimai qovluğa yazılır, bu da autentifikasiya olunmamış istifadəçilərə zərərli PHP faylları yükləyərək uzaqdan kod icrasına imkan verir. Plaginin təcili olaraq ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which versions of the Improve SEO plugin are affected by CVE-2026-16618?
This vulnerability affects the Improve SEO plugin up to version 2.0.11.
How is CVE-2026-16618 exploited and what is its impact?
Since validation only checks the file content type, an unauthenticated user can upload a malicious PHP file. The plugin writes it to a publicly accessible directory with an attacker-supplied extension, leading to Remote Code Execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.