CVE-2025-26776: WordPress Chaty Pro Plugin <= 3.3.3 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro chaty-pro allows Upload a Web Shell to a Web Server.This issue affects Chaty Pro: from n/a through <= 3.3.3.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Chaty Proto a version that resolves this vulnerability.Fixed in 3.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26776?
The severity of CVE-2025-26776 is considered high due to its potential for remote code execution via file upload.
How do I fix CVE-2025-26776?
To fix CVE-2025-26776, update Chaty Pro to version 3.3.4 or later, which mitigates the file upload vulnerability.
Which versions are affected by CVE-2025-26776?
CVE-2025-26776 affects NotFound Chaty Pro versions up to and including 3.3.3.
Can CVE-2025-26776 be exploited remotely?
Yes, CVE-2025-26776 can be exploited remotely, allowing attackers to upload web shells to the server.
Is CVE-2025-26776 specific to WordPress?
CVE-2025-26776 also affects the WordPress Chaty Pro Plugin versions up to and including 3.3.3.