#Arbitrary File Upload
All CosmicBytez Labs articles tagged #Arbitrary File Upload, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-82901: Ultra Addons for Contact Form 7 Arbitrary File Upload
Ultra Addons for Contact Form 7 (≤ 3.5.50) allows unauthenticated arbitrary file upload via a weakly validated PDF Generator signature field, enabling RCE.
- News
Hackers Exploit Critical WooCommerce Wholesale Lead Capture Flaw to Plant PHP Backdoors
Hackers exploit a critical flaw in the WooCommerce Wholesale Lead Capture plugin to upload PHP backdoors; Wordfence has blocked 100,000+ attacks.
- Security
CVE-2026-71805: LZ-litchi Unauthenticated Arbitrary File Upload
LZ-litchi 1.0.0 lets unauthenticated attackers upload arbitrary files outside the storage directory via a path-traversal flaw in its upload API.
- Security
CVE-2026-75865: WPLP Cookie Consent Plugin Unauthenticated File Upload
A critical flaw in the WPLP Cookie Consent WordPress plugin lets unauthenticated attackers upload arbitrary files, opening a path to remote code execution.
- Security
CVE-2026-80235: EFence Unauthenticated Arbitrary File Upload to RCE
EFence by Thinking Software Technology allows unauthenticated remote attackers to upload web shells and achieve full code execution.
- Security
Critical File Upload RCE in Templatiq WordPress Plugin (CVE-2026-32474)
CVE-2026-32474 allows Contributor-level users to upload arbitrary files in Templatiq <= 0.2.5, enabling remote code execution. CVSS score: 9.9.
- Security
CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload
A critical unauthenticated arbitrary file upload vulnerability in the Super Forms plugin for WordPress (CVSS 9.8) allows attackers to upload and execute...
- Security
CVE-2026-15282: WordPress Instant Appointment Plugin Critical File Upload
A critical unauthenticated arbitrary file upload flaw (CVSS 9.8) in the Instant Appointment WordPress plugin allows attackers to upload and execute...
- Security
CVE-2026-6885: Borg SPM 2007 Arbitrary File Upload Enables
A critical arbitrary file upload vulnerability in the end-of-life Borg SPM 2007 application allows unauthenticated attackers to upload web shell backdoors...