CVE-2026-32463: WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability
Published Aug 18, 2026
·Updated
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Affected Software
1 affected component
WordPress Sync Post With Other Site<=1.9.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Sync Post With Other Siteto a version that resolves this vulnerability.Fixed in 1.9.3
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using Sync Post With Other Site version 1.9.3 or earlier are affected. Exploitation requires an authenticated WordPress account with Contributor-level access.
2
What access does an attacker need to exploit it?
An attacker needs Contributor privileges but does not need user interaction. The vulnerability is remotely exploitable with low attack complexity and can affect confidentiality, integrity, and availability.