CVE-2026-66447: Critical SQL Injection in the WordPress File Upload Plugin

This text was generated using artificial intelligence (AI).On August 6, 2026, a critical security vulnerability was discovered in the WordPress plugin „WordPress File Upload“ with the identifier CVE-2026-66447 published. According to the Patchstack advisory, the vulnerability has a CVSS score of 9.3 (Critical) and allows attackers to perform an SQL injection without prior authentication. Since the plugin is used on many websites to provide file upload functionality, the vulnerability poses a significant risk to the confidentiality of database content.

Are my systems affected? Check now →