Back

CRITICAL

Omni Secure Files < 0.1.14 Unauthenticated Arbitrary File Upload

Published Jan 16, 2026

Description

Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file type restrictions, enabling an attacker to place attacker-controlled files under the plugin's uploads directory. This can lead to remote code execution if a server-executable file type is uploaded and subsequently accessed.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 16, 2026
Updated Apr 7, 2026
Reserved Jan 16, 2026
CISA Vulnrichment
Updated Jan 16, 2026
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a