CVE-2026-28133: WordPress Filr plugin <= 1.2.14 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28133?
CVE-2026-28133 is classified as a high severity vulnerability due to its potential for arbitrary file upload leading to web shell access.
How do I fix CVE-2026-28133?
To fix CVE-2026-28133, update the WordPress Filr plugin to a version higher than 1.2.12.
What types of files can be uploaded due to CVE-2026-28133?
CVE-2026-28133 allows the upload of files with dangerous types, including executable scripts that can lead to remote code execution.
What are the impacts of exploiting CVE-2026-28133?
Exploiting CVE-2026-28133 can result in unauthorized access to the web server, data breach, and the potential for full server compromise.
Is my WordPress site vulnerable to CVE-2026-28133?
If you are using the WordPress Filr plugin version 1.2.12 or earlier, your site is vulnerable to CVE-2026-28133.