WordPress security by component
zportals
zportals (zportals) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
zportalsLatest vulnerability
CVE-2026-14553: zportals subscriber uploads permit remote code execution
zportals before 6.3.4 trusts the client-supplied content type for an uploaded file and preserves its original extension. Any authenticated user, including a Subscriber, can therefore upload a PHP file that may execute under the web server and provide remote code execution. This unscored record received deeper review because a low-privilege arbitrary-file-upload primitive can lead directly to code execution. The CNA does not disclose the endpoint, action, upload field or destination directory.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-14553
zportals subscriber uploads permit remote code execution
zportals before 6.3.4 trusts the client-supplied content type for an uploaded file and preserves its original extension. Any authenticated user, including a Subscriber, can therefore upload a PHP file that may execute under the web server and provide remote code execution. This unscored record received deeper review because a low-privilege arbitrary-file-upload primitive can lead directly to code execution. The CNA does not disclose the endpoint, action, upload field or destination directory.
|
6.3.4 |
CVE8.1
NVDPending
|