CVE-2026-1756
Last modified
CVE-2026-1756 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::file_and_ext' function in all versions up to, and including, 2.1.39. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::file_and_ext' function in all versions up to, and including, 2.1.39. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1756?
How severe is CVE-2026-1756?
How do I fix CVE-2026-1756?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-17550A maliciously crafted DWG or DXF file, when parsed through A…5.5
- CVE-2026-17552Plack::App::Prerender versions before 0.3.0 for Perl can pro…9.1
- CVE-2026-17553The WP EasyCart plugin for WordPress is vulnerable to privil…7.2
- CVE-2026-17555The WPvivid Backup & Migration plugin for WordPress is vulne…4.9
- CVE-2026-17556A path traversal vulnerability was identified in GitHub Ente…9.1
- CVE-2026-17559The Passster WordPress plugin before 4.3.9 does not correctl…5.3
- CVE-2026-17561Improper Control of Generation of Code ('Code Injection') vu…9.8
- CVE-2026-17562Authorization bypass through User-Controlled key vulnerabili…6.5
- CVE-2026-17563The User Frontend WordPress plugin before 4.3.11 does not en…5.3
- CVE-2026-17565The Animation Addons for Elementor WordPress plugin before …7.2
- CVE-2026-17566pgAdmin 4's Import/Export Data tool builds a psql \copy (...…9.9
- CVE-2026-17567The Fluent Forms – Customizable Contact Forms, Survey, Quiz,…5.3
Are you affected by CVE-2026-1756?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
