CVE-2026-27064: WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability
Published Jul 23, 2026
·Updated
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Affected Software
1 affected component
WordPress Mailster plugin<=4.1.17
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mailster pluginto a version that resolves this vulnerability.Fixed in 4.1.18
Event History
Jul 23, 2026
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27064?
CVE-2026-27064 has a critical severity rating of 9.1.
2
How do I fix CVE-2026-27064?
To fix CVE-2026-27064, upgrade the WordPress Mailster plugin to version 4.1.18 or above.
3
What impact does CVE-2026-27064 have on my WordPress website?
CVE-2026-27064 allows arbitrary file uploads, potentially enabling attackers to compromise your server.
4
Is my site vulnerable if I am using an outdated Mailster plugin version?
Yes, using Mailster plugin version 4.1.17 or below makes your site vulnerable to CVE-2026-27064.
5
Who is affected by CVE-2026-27064?
Any WordPress users utilizing the Mailster plugin version 4.1.17 or earlier are affected by CVE-2026-27064.