CVE-2026-66447: SQL Injection in WordPress File Upload
This text was generated using artificial intelligence (AI).CVE-2026-66447 affects the plugin WordPress File Upload (wp-file-upload) by nickboss up to and including version 5.1.7. The vulnerability allows for an unauthenticated SQL injection via the parameter uniqueuploadid. Version 5.1.8 fixes the issue.
The vulnerability was published on August 6, 2026. Patchstack (CNA) rates the vulnerability with a CVSS score of 9.3 (Critical); the value is recorded in NVD. Active exploitation is not indicated.
The vulnerability is classified as CWE-89 classifies. According to Patchstack, the parameter uniqueuploadid is not sufficiently sanitized before being used in an SQL statement.
The CVSS vector is:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
This makes the issue accessible over the network, requires no authentication, and no user interaction. The score indicates high impact on confidentiality, no impact on integrity, and limited impact on availability. The EPSS value is around 0.23–0.24 %, indicating a currently low empirical exploitation probability; however, the lack of authentication requirement (AV:N/PR:N) still justifies timely prioritization.
Affected installations prioritize
Installations of the plugin WordPress File Upload up to and including version 5.1.7. are affected. The documented fix is available from version 5.1.8 onwards.
The following steps are planned for processing:
Update WordPress File Upload to version 5.1.8 or higher.
Prioritize and mitigate installations up to and including version 5.1.7 .
Consider the mitigation rule available from Patchstack.
Establish continuous vulnerability and vendor risk monitoring.
The lack of authentication requirement and the network accessibility are relevant in the prioritization. It is crucial to capture all known WordPress installations with the affected plugin.
For operators in the EU, it should be noted: If a successfully exploited SQL injection leads to the leakage of personal data, a reporting obligation to the responsible data protection authority applies within 72 hours according to Art. 33 GDPR. For NIS-2-mandated entities in Germany and Austria – implemented in Germany through the BSIG – there may also be a reporting obligation to the BSI. Organizations in Switzerland are subject to the revised Information Security Act (ISG) with a reporting obligation to the BACS.
WordPress plugin paths and metadata can provide indications of publicly accessible installations. LocateRisk makes exposed systems and deployed software visible under corporate domains. This external visibility supports the assignment of WordPress assets to responsible areas and the verification of whether the affected plugin is in use.
The visibility of a software component alone does not prove that a specifically vulnerable version is being operated. For CVE-2026-66447, the verification of whether WordPress File Upload is used on a detected WordPress installation up to and including version 5.1.7 remains relevant.
Continuous vendor risk monitoring complements technical processing, as security updates of deployed components can be considered in the risk process.
Am I affected?
Affected is WordPress File Upload in the versions mentioned above; the vulnerability has been fixed in 5.1.8. Anyone who wants to know whether WordPress File Upload is even visible in their own externally accessible infrastructure can consult the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-66447 refers to an unauthenticated SQL injection vulnerability in the WordPress plugin „WordPress File Upload“ (wp-file-upload) by nickboss. It allows attackers to inject arbitrary SQL statements without having to log in first. The CVSS score is 9.3 (Critical). uniqueuploadid . The vulnerability is fixed in version.
All versions of the plugin up to and including are affected. 5.1.7. Operators should update the plugin immediately to this version or higher. 5.1.8 Check whether the plugin.
is installed and active in a version ≤ 5.1.7. Since the vulnerability can be exploited from the network without authentication and without user interaction, the update to version 5.1.8 should also be prioritized even if there are currently no signs of exploitation. wp-file-upload in einer Version ≤ 5.1.7 installiert und aktiv ist. Da die Schwachstelle ohne Authentifizierung und ohne Nutzerinteraktion aus dem Netzwerk ausnutzbar ist, sollte die Aktualisierung auf Version 5.1.8 auch dann priorisiert werden, wenn bislang keine Anzeichen einer Ausnutzung vorliegen.
Status: October 01, 2026. This article is for general informational purposes and is not legal, security, or action advice for individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always decisive. Despite careful research, we do not guarantee the timeliness, accuracy, or completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-66447
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.