CVE-2026-14553: Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14553?
CVE-2026-14553 has a risk rating of 82, indicating it is a high-severity vulnerability.
How do I fix CVE-2026-14553?
To fix CVE-2026-14553, upgrade the Zportals WordPress plugin to version 6.3.4 or later.
Who is affected by CVE-2026-14553?
Any authenticated user with Subscriber or higher privileges in the Zportals WordPress plugin is affected by CVE-2026-14553.
What is the impact of CVE-2026-14553?
CVE-2026-14553 allows authenticated users to upload arbitrary PHP files, potentially leading to remote code execution.
What kind of vulnerability is CVE-2026-14553 classified as?
CVE-2026-14553 is classified as a Malicious File Upload vulnerability.