CVE-2026-32524: WordPress Photo Engine plugin <= 6.4.9 - Arbitrary File Upload vulnerability
Published Mar 25, 2026
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.
Affected Software
1 affected component
Jordy Meow Photo Engine<=6.4.9
Event History
Mar 25, 2026
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-32524?
CVE-2026-32524 is classified as a high severity vulnerability due to the potential for arbitrary file uploads.
2
How do I fix CVE-2026-32524?
To fix CVE-2026-32524, update the Jordy Meow Photo Engine plugin to version 6.5.0 or later.
3
What type of vulnerability is CVE-2026-32524?
CVE-2026-32524 is an Arbitrary File Upload vulnerability that allows attackers to upload files with dangerous types.
4
Who is affected by CVE-2026-32524?
CVE-2026-32524 affects users of the Jordy Meow Photo Engine plugin versions up to and including 6.4.9.
5
What can attackers do with CVE-2026-32524?
Attackers exploiting CVE-2026-32524 can upload a web shell to the web server, potentially gaining unauthorized access.