Back

CRITICAL

Uploadify <= 1.0 Unauthenticated Arbitrary File Upload

Published Jan 15, 2026

Description

Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution by uploading executable content to a web-accessible location.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 15, 2026
Updated May 14, 2026
Reserved Jan 15, 2026
CISA Vulnrichment
Updated Jan 20, 2026
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a