CVE-2026-39755
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVSS
9.9
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-434
Sin historial EPSS suficiente todavía.
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-3977010.0 CRÍ—
———Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.9hCVE-2026-397599.9 CRÍ—
———Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.9hCVE-2026-397579.9 CRÍ—
———Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.9hCVE-2026-3257910.0 CRÍ—
———Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.9hCVE-2026-1057018.8 ALT—
———The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions.13hCVE-2026-1056797.3 ALT—
——0Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.1d