CVE-2026-32559: WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability
Published Aug 24, 2026
·Updated
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Affected Software
1 affected component
WordPress UltimateAI<=3.1.0
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs low-level authenticated access, identified as Subscriber-level access. The attack can be performed over the network with low complexity and does not require user interaction.
2
Which installations are affected?
WordPress sites using UltimateAI version 3.1.0 or earlier are affected. Check the installed UltimateAI plugin version to determine exposure.
3
What could a successful exploit allow?
Successful exploitation may result in high impact to confidentiality, integrity, and availability. The vulnerability is associated with malicious file upload and has a critical severity score of 9.9.