Description
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Published: 2026-10-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Data Compromise
Action: Immediate Patch
AI Analysis

Impact

The WordPress File Upload plugin, versions 5.1.10 and earlier, contains an unauthenticated SQL Injection flaw (CWE‑89). An attacker can inject arbitrary SQL statements through the plugin’s upload functionality, potentially reading, modifying, or deleting database contents. This can lead to a full compromise of the website’s data, including user credentials and sensitive configuration information, and may also allow a malicious user to elevate privileges or alter site behavior.

Affected Systems

Anyone hosting a WordPress site that has the WordPress File Upload plugin installed and has a version ≤ 5.1.10 is at risk. The plugin is developed by nickboss and distributed through the WordPress plugin repository. The vulnerability affects all installations that rely on the default upload handling of the plugin without additional safeguards.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. The plugin exposes the flaw to unauthenticated users, lowering the required skill level and barrier to exploitation. Although EPSS data is not available and the issue is not currently listed in the CISA KEV catalog, the public availability of this flaw makes the risk high. Site owners should immediately update the plugin or otherwise restrict the upload capability to mitigate the vulnerability.

Generated by OpenCVE AI on October 1, 2026 at 16:00 UTC.

Remediation

Vendor Solution

Update the WordPress WordPress File Upload plugin to the latest available version (at least 5.2.0).


OpenCVE Recommended Actions

  • Update the WordPress File Upload plugin to version 5.2.0 or newer.
  • If updating is not immediately possible, disable the plugin or remove the upload feature for unauthenticated users until a patch is applied.
  • Review the upload handlers in the plugin’s configuration to ensure that no arbitrary file types are accepted and that file uploads are properly validated.

Generated by OpenCVE AI on October 1, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Title WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:06:25.257Z

Reserved: 2026-07-13T06:14:48.066Z

Link: CVE-2026-62071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:30.647

Modified: 2026-10-01T16:17:46.240

Link: CVE-2026-62071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:15:10Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')