← WordPress Vulnerabilities
WordPress security by component

LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock

LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock (lightsyncpro) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 8.8.

Plugin slug: lightsyncpro

CVE-2026-6147: LightSync Pro author media replacement permits arbitrary file uploads

LightSync Pro through 2.1.6 lets an authenticated Author reach rest_replace_media(), which accepts an uploaded replacement without validating its file type. An Author can therefore place an arbitrary file on the server; if the destination is executable by the web server, the upload can lead to remote code execution and full site compromise. The CNA does not disclose the REST route, HTTP method, upload parameter, media identifier or final file-write API.

PublishedAug 05, 2026
Known safe version> 2.1.6
Published vulnerabilities for lightsyncpro
Safe version
Aug 05, 2026 CVE-2026-6147
LightSync Pro author media replacement permits arbitrary file uploads
LightSync Pro through 2.1.6 lets an authenticated Author reach rest_replace_media(), which accepts an uploaded replacement without validating its file type. An Author can therefore place an arbitrary file on the server; if the destination is executable by the web server, the upload can lead to remote code execution and full site compromise. The CNA does not disclose the REST route, HTTP method, upload parameter, media identifier or final file-write API.
> 2.1.6
CVE8.8
NVDPending