CVE-2026-66627: WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GP Premium pluginto a version that resolves this vulnerability.Fixed in 2.5.6
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level access to a WordPress site using an affected GP Premium version. No user interaction is required once that access is available.
Which installations should be prioritized for remediation?
The affected version range is GP Premium 2.5.5 and earlier. Sites running those versions should be treated as exposed if Contributor accounts can access the vulnerable functionality.
What can be done if patching cannot happen immediately?
Review Contributor accounts and remove or restrict access for accounts that are not trusted while remediation is pending. Monitor for unexpected uploaded files, especially files that could be executed by the server.