Description
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
Published: 2026-09-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The Gpx2Graphics WordPress plugin version 0.3 does not perform a CSRF check when handling file uploads and does not validate the uploaded file type. A logged‑in administrator can be tricked into submitting an arbitrary file, such as a PHP script, enabling the attacker to execute code on the server. This flaw is identified as a CWE‑352 Cross‑Site Request Forgery and a CWE‑434 Arbitrary File Upload, and it permits the attacker to run malicious code on the affected site.

Affected Systems

Any WordPress installation that includes the Gpx2Graphics plugin at version 0.3 or earlier is vulnerable. Administrators who leave an active session while the plugin remains enabled are the primary target for exploitation.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity level, while the EPSS score of <1% suggests that exploitation is currently rare but still possible. The attack requires a CSRF request that a logged‑in administrator could unknowingly submit, and because the plugin accepts any file type, the attacker can upload and execute a PHP file. The vulnerability is not listed in the CISA KEV catalog, indicating no currently observed large‑scale exploitation, but the risk is theoretically high due to the nature of the flaw.

Generated by OpenCVE AI on September 15, 2026 at 18:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated version of Gpx2Graphics newer than 0.3 that implements proper CSRF protection and restricts file type uploads
  • If an update is not available, configure the server or topic‑specific settings to whitelist only safe file types for the plugin’s upload endpoint, or disable the upload capability for non‑trusted users
  • Implement site‑wide CSRF mitigation such as nonce tokens in forms or a web application firewall rule that blocks CSRF attempts against the upload endpoint

Generated by OpenCVE AI on September 15, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-434

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
Title Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:34:07.152Z

Reserved: 2026-08-26T15:56:30.258Z

Link: CVE-2026-81090

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:26.932Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:25.620

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-81090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-434

    Unrestricted Upload of File with Dangerous Type