OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-62071

CRITICAL · CVSS 9.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

WordPress versions up to 5.1.10 are vulnerable to an unauthenticated SQL injection flaw in the file upload functionality, allowing attackers to execute arbitrary SQL queries and potentially gain unauthorized access to sensitive data. This critical vulnerability, with a CVSS score of 9.3, poses a significant risk to websites using these versions, making it imperative for administrators to prioritize immediate updates to mitigate potential exploitation. All WordPress site owners and developers should address this issue promptly to safeguard their systems.

CVE
CVE-2026-62071
Severity
CRITICAL
CVSS
9.3
EPSS
0.24%
WordPress

Original NVD Description

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.