Back

HIGH

Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF

Published Sep 12, 2026

Description

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 12, 2026
Updated Sep 12, 2026
Reserved Aug 26, 2026
CISA Vulnrichment
Updated Sep 12, 2026
NVD
Status Deferred
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Sep 12, 2026
Updated Sep 12, 2026
Exploited since n/a
EUVD-2026-76783