What is CVE-2026-16985?
In Squeeze WordPress plugin versions before 1.7.12, a missing file type validation allows users with Author role or higher to write executable PHP files into the uploads directory. This leads to potential remote code execution (RCE), and updating the plugin is strongly recommended.
Azərbaycanca: Squeeze WordPress plaqininin 1.7.12-dən əvvəlki versiyalarında fayl tipi doğrulaması olmadığı üçün "Author" və yuxarı rollu istifadəçilər uploads qovluğuna icra edilə bilən PHP faylı yerləşdirə bilər. Bu, serverdə uzaqdan kod icrasına (RCE) səbəb olur, dərhal plaqini yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which user roles are affected by CVE-2026-16985 in the Squeeze plugin?
The vulnerability affects users with Author role or higher, allowing them to achieve RCE on the server via an unrestricted file upload.
How can I mitigate CVE-2026-16985?
It is strongly recommended to update the Squeeze plugin to version 1.7.12 or higher immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.