CVE-2026-66447: Critical SQL Injection in the WordPress File Upload Plugin
This text was generated using artificial intelligence (AI).On August 6, 2026, a critical security vulnerability was discovered in the WordPress plugin „WordPress File Upload“ with the identifier CVE-2026-66447 published. According to the Patchstack advisory, the vulnerability has a CVSS score of 9.3 (Critical) and allows attackers to perform an SQL injection without prior authentication. Since the plugin is used on many websites to provide file upload functionality, the vulnerability poses a significant risk to the confidentiality of database content.
The information is based on a report from Patchstack. As of the publication of this article, the entry in the National Vulnerability Database (NVD) had not yet been fully analyzed—Patchstack is therefore the only available primary source for the CVE ID, CVSS score, and affected versions.
Technical Background and Risk
The vulnerability stems from insufficient validation of user input before it is used in SQL database queries. This allows an attacker to send specially crafted requests to an affected website and inject their own SQL commands into the database.
The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L accurately describes the risk:
Attack Vector: Network (AV:N): The vulnerability can be exploited remotely without local access.
Privileges Required: None (PR:N): An attacker does not need a user account or any permissions.
User Interaction: None (UI:N): A successful attack does not require any interaction from a user or administrator.
This combination makes any publicly accessible WordPress instance running a vulnerable plugin version an easy target for attack. A successful attack can result in the extraction of sensitive information from the database, including user data, hashed passwords, page content, and configurations. The high confidentiality impact (Confidentiality: High, C:H) highlights this risk.
The nickboss plugin was repeatedly affected by critical vulnerabilities in 2024 and 2025: CVE-2024-11613 (Remote Code Execution, CVSS 9.8, all versions up to and including 4.24.15, reported in January 2025) and CVE-2024-9047 (path traversal, CVSS 9.8, up to version 4.24.11) demonstrate a recurring pattern of insufficient input validation in this plugin. Sources: NVD CVE-2024-11613, GitHub Advisory GHSA-c86g-pwgj-7qq3.
Recommendations for Operators
Organizations and administrators should immediately check whether the affected plugin is in use in their infrastructure. Due to the critical nature of the vulnerability, swift countermeasures are required.
Identification and Testing: Identify all WordPress instances in your system environment. Check whether the „WordPress File Upload“ plugin is installed and which version is being used.
Update: As of the publication of this article, no official patch has been announced. Administrators are advised to Patchstack Advisory Page Check regularly for available updates and install any available updates immediately.
Temporary Deactivation: Since no patch is currently available, temporarily disabling the plugin provides effective protection, as this removes the vulnerability.
Monitoring Log Files: Check web server and database logs for unusual or invalid SQL queries. Such entries may indicate attempted or successful exploits.
The following applies to operators of critical infrastructure or providers of digital services in the EU: If an actively exploited vulnerability leads to a personal data breach, there is an obligation under Article 33 of the GDPR to report the incident to the competent data protection authority within 72 hours. Companies subject to NIS 2 should be able to demonstrate their patching and response processes as part of their documented vulnerability management. The BSI generally recommends continuously inventorying the use of third-party plugins and immediately isolating unpatched components.
The Role of EASM in Addressing Plugin Vulnerabilities
Vulnerabilities such as CVE-2026-66447 highlight a key challenge for IT security: the lack of visibility into all publicly accessible systems and their software components. Especially in large or decentralized organizations, there are often WordPress instances that are not actively maintained—so-called “shadow IT” or forgotten websites that are simply not captured during a manual inventory process.
This is where External Attack Surface Management (EASM) comes into play. An EASM platform like LocateRisk continuously scans a company’s external attack surface and identifies all publicly accessible assets, including websites, servers, and their underlying technology. This allows the platform to detect where WordPress is being used, thereby providing a solid data foundation for quickly identifying potentially affected systems—even those that do not appear in any maintained inventory list.
This approach enables a targeted and prioritized response: security managers can directly notify the identified system owners and track the implementation of countermeasures. This shortens the response time and helps ensure that no overlooked systems remain unprotected. The repeated occurrence of critical vulnerabilities in this plugin—ranging from RCE to path traversal to SQL injection—further underscores the value of continuous third-party monitoring as part of a vendor risk management program. LocateRisk’s solution is hosted in German data centers and is designed to meet the requirements of the GDPR.
CVE-2026-66447 is a critical vulnerability in the „WordPress File Upload“ plugin by nickboss. It allows attackers to inject their own SQL commands into the database of an affected WordPress instance without any authentication. According to the Patchstack advisory, the vulnerability is rated with a CVSS score of 9.3 (critical).
According to the Patchstack advisory, all versions of the plugin up to and including 5.1.7 are affected. As of the publication of this article, no official patch is known to exist. The NVD entry is still under review.
Temporarily disable the „WordPress File Upload“ plugin until an official patch is available. Additionally, monitor your web server and database logs for signs of exploitation, and check the Patchstack Advisory regularly for new information.
As of August 6, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.