WordPress security by component
LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock
LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock (lightsyncpro) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
lightsyncproLatest vulnerability
CVE-2026-6147: LightSync Pro author media replacement permits arbitrary file uploads
LightSync Pro through 2.1.6 lets an authenticated Author reach rest_replace_media(), which accepts an uploaded replacement without validating its file type. An Author can therefore place an arbitrary file on the server; if the destination is executable by the web server, the upload can lead to remote code execution and full site compromise. The CNA does not disclose the REST route, HTTP method, upload parameter, media identifier or final file-write API.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-6147
LightSync Pro author media replacement permits arbitrary file uploads
LightSync Pro through 2.1.6 lets an authenticated Author reach rest_replace_media(), which accepts an uploaded replacement without validating its file type. An Author can therefore place an arbitrary file on the server; if the destination is executable by the web server, the upload can lead to remote code execution and full site compromise. The CNA does not disclose the REST route, HTTP method, upload parameter, media identifier or final file-write API.
|
> 2.1.6 |
CVE8.8
NVDPending
|