momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2026-1306: WordPress midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload

CVE: CVE-2026-1306
CNVD: 暂无
CNNVD: 暂无
漏洞类型: 命令执行
漏洞等级: 严重
年份: 2026
POC_ID: 暂无
漏洞描述
WordPress midi-Synth plugin \u003C= 1.1.0 contains an unrestricted file upload vulnerability caused by missing file type and extension validation in the 'export' AJAX action, letting unauthenticated attackers upload arbitrary files and potentially execute remote code, exploit requires attacker to obtain a valid nonce exposed in frontend JavaScript. [已公开] id: CVE-2026-1306 info: name: WordPress midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload author: pussycat0x severity: critical description: | WordPress midi-Synth plugin \u003C= 1.1.0 contains an unrestricted file upload vulnerability caused by missing file type and extension validation in the 'export' AJAX action, letting unauthenticated attackers upload arbitrary files and potentially execute remote code, exploit requires attacker to obtain a valid nonce exposed in frontend JavaScript. impact: | Unauthenticated attackers can upload arbitrary files and potentially execute remote code on the server. remediation: | Update to the latest version of midi-Synth plugin. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/midi-synth/midi-synth-110-unauthenticated-arbitrary-file-upload-via-expor
FOFA 语句
暂无
影响范围
WordPress midi Synth
漏洞详情
POC: 已公开
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无