CVE-2026-62024
Received Received - Intake

Subscriber Arbitrary File Upload in CodeBard Help Desk

Vulnerability report for CVE-2026-62024, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Patchstack

Description

Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CodeBard CodeBard Help Desk n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62024 is an Arbitrary File Upload vulnerability in the CodeBard Help Desk WordPress plugin versions 1.1.2 and below. It allows attackers with subscriber-level access to upload malicious files to the server, which can lead to full server compromise.

Detection Guidance

Check for unauthorized file uploads in the WordPress uploads directory, particularly files with unusual extensions or names. Review server logs for POST requests to /wp-admin/admin-ajax.php with suspicious parameters. Use tools like grep to search for 'subscriber' role actions in logs.

Impact Analysis

This vulnerability can allow attackers to upload malicious files, potentially leading to full server compromise. It poses a significant risk for mass-exploitation campaigns targeting WordPress sites, especially since there is no official patch available as of the report date.

Mitigation Strategies

Apply Patchstack's emergency mitigation rule if available. Restrict subscriber-level access to only trusted users. Monitor for unusual file uploads and server activity. Consider temporarily disabling the plugin until an official patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62024. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart