Back

HIGH

Squeeze < 1.7.12 - Author+ Arbitrary File Upload

Published Aug 10, 2026

Description

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Aug 10, 2026
Updated Aug 11, 2026
Reserved Jul 24, 2026

CISA Vulnrichment

Updated Aug 11, 2026

NVD

Status Deferred
Modified Aug 26, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Aug 10, 2026
Updated Aug 11, 2026

GitHub

No data