CVE-2026-62071: WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
Published Oct 1, 2026
·Updated
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Affected Software
1 affected component
WordPress WordPress File Upload<=5.1.10
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress File Upload pluginto a version that resolves this vulnerability.Fixed in 5.2.0
Event History
Oct 1, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated and remotely exploitable, so an attacker does not need a WordPress account or user interaction to attempt exploitation.
2
Which plugin versions are affected?
WordPress File Upload versions 5.1.10 and earlier are affected according to the available information.
3
What is the potential impact?
The issue is rated critical with a CVSS score of 9.3. The supplied vector indicates high confidentiality impact, no integrity impact, and low availability impact, with scope changed.