CVE-2026-62261
AI description
CVE-2026-6261 is an arbitrary file upload vulnerability found in the Betheme theme for WordPress, affecting versions up to and including 28.4. The flaw exists within the `upload_icons()` function, which is responsible for handling icon-pack uploads. This function processes user-supplied ZIP archives by moving and unzipping their contents into a public uploads directory without adequately validating the types of files being extracted. This vulnerability allows authenticated attackers with author-level access or higher to exploit the icon-pack upload workflow. By uploading a specially crafted ZIP file containing malicious PHP files, attackers can achieve remote code execution on the affected WordPress installation. The root cause is attributed to the lack of file type validation after archive extraction, as the handler trusts the contents of the user-supplied ZIP without enforcing an allowlist of file extensions or validating MIME types.
- Description
- -
- Hype score
- Not currently trending
OpenAMの脆弱性CVE-2026-62379(CVSS 9.8)は認証なしのリモートコード実行を可能にし、CVE-2026-62261はCVSS 9.9のスコアを獲得した OpenAM CVE-2026-62379 (CVSS 9.8) Enables Unauthenticated Remote Code Execution, CVE-2026-62261 Scores CVSS 9.9 #Dai
@foxbook
3 Aug 2026
289 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 OpenAM 16.1.2 patches 4 vulnerabilities, including CVE-2026-62379 (CVSS 9.8), which could allow unauthenticated RCE, and CVE-2026-62261 (CVSS 9.9). No active exploitation or public PoC has been reported. 🔗 https://t.co/uPAHkIzA5a #OpenAM #RCE #CVE #CyberSecurity
@ThreatWire_
1 Aug 2026
739 Impressions
2 Retweets
13 Likes
3 Bookmarks
0 Replies
0 Quotes
Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9. #OpenAM #RCE #IAM #CVE202662379 https://t.co/zjT9OK4mBy
@Daily_CyberSec
31 Jul 2026
491 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes