← WordPress Vulnerabilities
WordPress security by component

zportals

zportals (zportals) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 8.1.

Plugin slug: zportals

CVE-2026-14553: zportals subscriber uploads permit remote code execution

zportals before 6.3.4 trusts the client-supplied content type for an uploaded file and preserves its original extension. Any authenticated user, including a Subscriber, can therefore upload a PHP file that may execute under the web server and provide remote code execution. This unscored record received deeper review because a low-privilege arbitrary-file-upload primitive can lead directly to code execution. The CNA does not disclose the endpoint, action, upload field or destination directory.

PublishedAug 05, 2026
Known safe version6.3.4
Published vulnerabilities for zportals
Safe version
Aug 05, 2026 CVE-2026-14553
zportals subscriber uploads permit remote code execution
zportals before 6.3.4 trusts the client-supplied content type for an uploaded file and preserves its original extension. Any authenticated user, including a Subscriber, can therefore upload a PHP file that may execute under the web server and provide remote code execution. This unscored record received deeper review because a low-privilege arbitrary-file-upload primitive can lead directly to code execution. The CNA does not disclose the endpoint, action, upload field or destination directory.
6.3.4
CVE8.1
NVDPending