Overview
A high-severity remote code execution vulnerability has been disclosed in wcms, the lightweight PHP content management system maintained by vincent-peugnet. Tracked as CVE-2026-105123 and classified under CWE-434 (Unrestricted Upload of File with Dangerous Type), the flaw lives in the media management API and lets an authenticated user holding only the Editor role write arbitrary files to the server, including executable .php scripts.
The vulnerable endpoint is POST /api/v0/media/upload/[**:path], where the trailing path segment is passed through to the filesystem layer without adequate validation or canonicalization. By combining a .php filename with directory traversal sequences, a low-privileged editor can place a web shell somewhere the server will actually execute it, turning a content-management permission into full remote code execution as the web server process. A companion endpoint, DELETE /api/v0/media/[**:path], shares the same unsanitized path handling and permits arbitrary file deletion.
The issue was publicly disclosed on October 4, 2026, as part of a broader report (GitHub issue #662) covering multiple high-severity wcms flaws — unrestricted upload leading to RCE, path traversal, stored XSS, and missing CSRF protections — all affecting wcms through version 3.18.0.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105123 |
| CWE | CWE-434: Unrestricted Upload of File with Dangerous Type (compounded by CWE-22: Path Traversal) |
| Severity | High |
| CVSS Score | 8.8 (CVSS 3.1) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network (media upload/delete API) |
| Authentication | Required (authenticated session) |
| Privileges Required | Low (Editor role) |
| User Interaction | None |
| Affected Software | vincent-peugnet/wcms ≤ 3.18.0 |
| Fixed Version | wcms 3.18.1 |
How It Works
wcms exposes a media management API for editors to upload, move, rename, and delete files used in site content. Two routes are implicated:
POST /api/v0/media/upload/[**:path]— accepts a file upload where the destination path is taken directly from the URL's trailing path parameter.DELETE /api/v0/media/[**:path]— accepts the same style of path parameter to identify a file for deletion.
The backend containment check (in app/class/Controllerapimedia.php and the filesystem helpers in Fs.php) relies on a naive string check — effectively strpos($dir,'media/')!==0 — to confirm a path stays inside the intended media directory. That check can be bypassed with sequences like media/../../, and with URL-encoded traversal (%2e%2e%2f), because the path is never resolved to a canonical form before the comparison runs.
Exploitation proceeds in two steps:
- Arbitrary write. An authenticated Editor sends a crafted upload request with a
.phpfilename and a traversal-laden path. Because wcms does not enforce a file-extension allowlist on the upload handler, the server writes the attacker's PHP file to a location of the attacker's choosing — including directories the web server will interpret and execute, rather than just the intended media/asset store. - Execution. A follow-up HTTP request to the uploaded file's path causes the web server to execute the PHP payload, giving the attacker code execution with the privileges of the web server process — access to the database credentials in configuration files, the ability to pivot to other services on the host, and a durable backdoor independent of the CMS's own authentication.
The same unsanitized path handling in the DELETE route additionally lets an authenticated editor remove files outside the media directory, creating a secondary denial-of-service path (e.g., deleting application or configuration files needed for wcms to run).
Related vulnerable code paths flagged in the disclosure include app/class/Media.php, app/class/Modelmedia.php (multifiledelete, movefile, rename, deletedir), and app/class/Controllermedia.php, all of which perform directory-scoped operations without canonical-path validation.
Impact Assessment
| Impact Area | Description |
|---|---|
| Remote Code Execution | Attacker-uploaded .php web shell executes with web server privileges once placed in an executable, web-accessible path |
| Arbitrary File Write | Encoded ../ traversal sequences let the attacker write files anywhere the web server process can reach, not just inside the media directory |
| Arbitrary File Deletion | The companion DELETE endpoint accepts the same unsanitized path, enabling deletion of files outside the media directory |
| Credential/Data Exposure | RCE enables reading database credentials and other secrets from configuration files on disk |
| Availability | Deletion of core application or configuration files can crash or disable the CMS |
| Low Bar to Exploit | Only a low-privileged Editor account is required — not an administrator — and no user interaction is needed |
Who Is At Risk
Any self-hosted wcms deployment on version 3.18.0 or earlier is at risk if it grants the Editor role to anyone who isn't fully trusted — a common situation for CMS platforms with multiple content contributors, freelance writers, or external agencies. Realistic exposure scenarios include:
- Multi-editor sites where Editor accounts are issued to contributors outside the core admin team
- Shared or multi-tenant hosting where compromise of one wcms instance could be used to pivot further
- Any internet-facing wcms instance where the media API is reachable without additional network-layer restriction
Because exploitation requires only Editor-level access and no further privilege escalation, organizations that treat "Editor" as a low-trust role should re-evaluate that assumption until patched.
Mitigation
Immediate Actions
- Upgrade to wcms 3.18.1 or later, which addresses the path validation gap in the media upload and delete handlers.
- Audit existing media/upload directories for unexpected
.phpfiles or other executable content that may already have been planted. - Review Editor role assignments and revoke access for any account that doesn't need content-management privileges.
For Administrators
- Configure the web server to deny PHP execution inside media/upload directories (e.g., an Apache
.htaccessrule or an nginxlocationblock disabling the PHP handler for that path) as defense in depth, independent of the application-level fix. - Rotate database and application credentials if any evidence of unauthorized file writes is found.
- Enforce MFA on all CMS accounts, especially Editor and Admin roles, to reduce the chance of account takeover feeding this vulnerability.
For Developers Running or Forking wcms
- Validate all user-supplied path parameters with
realpath()and verify the result starts withrealpath(MEDIA_DIR)before any filesystem operation — never rely on string-prefix checks likestrpos()for containment. - Enforce a strict file-extension allowlist (images, documents) on the upload handler and reject anything else, including disguised or double extensions.
- Store uploaded media outside the web root, or serve it through a handler that never executes server-side code, so even a successful path-traversal write can't result in execution.
For Security Teams
- Add wcms to your software inventory if used internally or by any customer-facing sites you operate or audit.
- Monitor web server and application logs for
POSTrequests to/api/v0/media/upload/containing../, URL-encoded traversal (%2e%2e%2f), or.php/executable extensions. - Consider a WAF rule blocking traversal sequences and non-media file extensions on the wcms media API endpoints until all instances are patched.
Key Takeaways
- CVE-2026-105123 is a CVSS 8.8 High severity vulnerability in vincent-peugnet/wcms ≤ 3.18.0, classified under CWE-434 and compounded by a path-traversal weakness (CWE-22).
- The flaw lives in the media API's path handling —
POST /api/v0/media/upload/[**:path]andDELETE /api/v0/media/[**:path]— which fails to canonicalize or validate the path parameter. - A low-privileged, authenticated Editor account is sufficient to upload a
.phpweb shell and traverse outside the media directory, achieving remote code execution as the web server process. - The same bug in the DELETE route allows arbitrary file deletion, creating a secondary denial-of-service risk.
- wcms 3.18.1 fixes the issue. There is no public proof-of-concept and the CVE is not listed in CISA's KEV catalog as of publication, but low attack complexity and no required user interaction make prompt patching important.
- This CVE is part of a larger disclosure (GitHub issue #662) covering multiple high-severity wcms issues — treat the fix as part of a full upgrade, not a single-CVE patch.