CVE-2026-81090
Received Received - Intake

Gpx2Graphics WordPress Plugin Arbitrary File Upload to RCE

Vulnerability report for CVE-2026-81090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gpx2graphics gpx2graphics to 0.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-81090 is a vulnerability in the Gpx2Graphics WordPress plugin version 0.3 or below. It lacks CSRF protection and file type validation during file uploads. Attackers can trick a logged-in administrator into uploading malicious files like PHP, leading to Remote Code Execution on the server.

Detection Guidance

Check if the Gpx2Graphics plugin version 0.3 or below is installed on your WordPress site. Inspect network traffic for suspicious file upload requests from administrators. Look for unexpected PHP or executable files in upload directories.

Impact Analysis

This vulnerability allows attackers to execute arbitrary code on your server by uploading malicious files. If you use the affected plugin, an attacker could gain control over your WordPress site, steal data, or use it for further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements like GDPR and HIPAA. It may result in data exposure, legal penalties, and reputational damage due to compromised sensitive information.

Mitigation Strategies

Immediately disable or uninstall the Gpx2Graphics plugin if installed. Monitor for unauthorized file uploads. Apply any available patches once released. Restrict file upload permissions for administrators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart