CVE-2026-26212
Awaiting Analysis Awaiting Analysis - Queue

Arbitrary File Upload in Rara One Click Demo Import WordPress Plugin

Vulnerability report for CVE-2026-26212, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP files by passing a false value to wp_handle_upload() that disables WordPress core's file type validation checks across all three file parameters in the process_uploaded_files() function. Attackers can upload a malicious PHP file to the uploads directory and execute it over HTTP to achieve remote code execution in the web server process, with the uploaded file persisting on disk even after plugin deactivation and leaving no media library record to evade standard integrity checks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rara_themes rara_one_click_demo_import to 1.3.5 (exc)
rara_one_click_demo_import 1.3.5 to 1.3.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an arbitrary file upload flaw in the Rara One Click Demo Import WordPress plugin before version 1.3.5. It allows authenticated attackers with Administrator privileges to bypass WordPress core's file type validation checks and upload malicious PHP files to the server. These files can be executed remotely to achieve code execution on the web server. The uploaded files persist even after plugin deactivation and leave no record in the media library, making detection difficult.

Detection Guidance

Check if the Rara One Click Demo Import plugin version is below 1.3.5. Look for unexpected PHP files in the WordPress uploads directory. Review server access logs for suspicious file uploads or execution attempts.

Impact Analysis

If you are an administrator of a WordPress site using the vulnerable plugin version, attackers could gain full control over your website by uploading and executing malicious PHP files. This could lead to complete compromise of the site, data theft, defacement, or use as a pivot point for further attacks. The persistent nature of the uploaded files means the threat remains even after plugin updates.

Compliance Impact

This vulnerability allows authenticated attackers with Administrator privileges to upload and execute arbitrary PHP files on the server. This could lead to unauthorized access, data exfiltration, or modification of sensitive data, which would violate compliance requirements under GDPR (data protection) and HIPAA (protected health information). The persistence of uploaded files even after plugin deactivation further increases the risk of undetected breaches.

Mitigation Strategies

Update the Rara One Click Demo Import plugin to version 1.3.5 or later immediately. Remove any unauthorized PHP files from the uploads directory. Restrict Administrator privileges to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-26212. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart