CVE-2026-16618
9.8 CRITICALPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw allows unauthenticated users to upload executable PHP files, leading to remote code execution due to improper file validation.
- Exploitability
- Exploitation is relatively easy as it requires uploading a file with a specific content type and extension, which can be automated.
- Blast radius
- If exploited, the impact could be severe, as it allows attackers to execute arbitrary code on the server, potentially leading to full control of the affected WordPress site.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 2.12 or later.
rcewebphpwordpress
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-75799
- HIGHCVE-2026-14553
- CRITICALCVE-2026-70356PoC
- CRITICALCVE-2026-82187
- CRITICALCVE-2026-82901
- CRITICALCVE-2026-93352PoC
- HIGHCVE-2026-94104PoC
- CRITICALCVE-2026-12227
Related by shared AI tags and CWE weakness class. Browse the full archive.