← Back to search

CVE-2026-16618

9.8 CRITICAL

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw allows unauthenticated users to upload executable PHP files, leading to remote code execution due to improper file validation.
Exploitability
Exploitation is relatively easy as it requires uploading a file with a specific content type and extension, which can be automated.
Blast radius
If exploited, the impact could be severe, as it allows attackers to execute arbitrary code on the server, potentially leading to full control of the affected WordPress site.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 2.12 or later.
rcewebphpwordpress

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.