CVE-2026-26212: Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE

Published Sep 9, 2026
·
Updated

Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP files by passing a false value to wphandleupload() that disables WordPress core's file type validation checks across all three file parameters in the processuploadedfiles() function. Attackers can upload a malicious PHP file to the uploads directory and execute it over HTTP to achieve remote code execution in the web server process, with the uploaded file persisting on disk even after plugin deactivation and leaving no media library record to evade standard integrity checks.

Affected Software

1 affected component
Rara Rara One Click Demo Import<1.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wordpress/Rara One Click Demo Import to a version that resolves this vulnerability.

    Fixed in 1.3.5
  2. Compensating control

    Because the vulnerability can be exploited by authenticated users with Administrator privileges, restrict/limit Administrator access for WordPress accounts to trusted users and reduce the number of accounts with Administrator roles.

Event History

Sep 9, 2026
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated WordPress user with Administrator privileges can exploit it. The attacker must be able to access the plugin's upload functionality and then request the uploaded PHP file over HTTP.

2

Are standard WordPress file-type protections sufficient?

No. The affected plugin disables WordPress core file-type validation during its upload processing, allowing arbitrary PHP files to be uploaded to the uploads directory.

3

What evidence should administrators look for if compromise is suspected?

Check the WordPress uploads directory for unexpected PHP files, including files that do not have corresponding Media Library entries. Uploaded malicious files can remain on disk after the plugin is deactivated, so deactivation alone does not remove them.

4

What should be done if the plugin cannot be updated immediately?

Restrict Administrator access to trusted users and prevent HTTP execution of PHP files in the uploads directory where possible. Review the uploads directory for unauthorized PHP files and remove any confirmed malicious files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203