CVE-2026-66447: SQL Injection in WordPress File Upload

This text was generated using artificial intelligence (AI).CVE-2026-66447 affects the plugin WordPress File Upload (wp-file-upload) by nickboss up to and including version 5.1.7. The vulnerability allows for an unauthenticated SQL injection via the parameter uniqueuploadid. Version 5.1.8 fixes the issue.

The vulnerability was published on August 6, 2026. Patchstack (CNA) rates the vulnerability with a CVSS score of 9.3 (Critical); the value is recorded in NVD. Active exploitation is not indicated.

Are my systems affected? Check now →