What is CVE-2026-66627?
An arbitrary file upload vulnerability has been found in GP Premium plugin (<= 2.5.5 versions) that can be exploited by users with Contributor role. This could lead to remote code execution; updating to the latest version is strongly recommended.
Azərbaycanca: GP Premium plaginində (2.5.5 və aşağı versiyalar) Contributor səlahiyyətinə malik istifadəçinin icazəsiz fayl yükləməsi zəifliyi aşkar edilib. Bu, uzaqdan kod icrasına səbəb ola bilər, plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which versions of the GP Premium plugin are affected by CVE-2026-66627?
This vulnerability affects GP Premium plugin versions 2.5.5 and below.
What privilege level is required to exploit CVE-2026-66627?
This vulnerability can be exploited by a user with the Contributor role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.