CVE-2026-63444
AI description
CVE-2026-63444 is identified as a path traversal vulnerability within the Fluent Forms plugin for WordPress, affecting all versions up to and including 6.2.1. This flaw is located in the `getAttachments()` method of `EmailNotificationActions`, which is responsible for resolving file-upload URLs into filesystem paths. The vulnerability arises from insufficient path validation, allowing for arbitrary file read access. Authenticated attackers with administrator privileges can exploit this vulnerability by submitting a form configured to attach a file-upload field. By supplying a specially crafted URL as the file-field value, they can bypass the validation checks and read arbitrary files accessible to the web-server user, such as `wp-config.php`, which may contain sensitive information like database credentials and authentication salts. The targeted file is then silently attached to outbound administrator notification emails.
- Description
- -
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5