AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14553

HIGH · CVSS 8.1 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The zportals WordPress plugin prior to version 6.3.4 is vulnerable due to inadequate validation of uploaded files, allowing authenticated users (Subscribers and above) to upload arbitrary PHP files with preserved extensions. This flaw can lead to remote code execution, posing significant risks to the integrity and security of the WordPress site. WordPress administrators and security teams should prioritize updating to the latest version to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14553
Severity
HIGH
CVSS
8.1
EPSS
0.43%
WordPress

Original NVD Description

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.