External risk intelligence

Unauthenticated SQL Injection in WordPress File Upload Plugin

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-62071

This vulnerability affects a WordPress plugin, which functions as an internet-facing web component. Because it allows for unauthenticated SQL injection, it is directly reachable via public web requests, making it a service exposed to the internet by design in typical deployments.

SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a widely used WordPress plugin, potentially exposing sensitive data through unauthenticated SQL injection. This issue allows unauthorized access to databases without requiring any login credentials.

  • Unauthenticated database access via a popular plugin.
  • Critical exposure without user interaction.
  • Confirm relevance and assess potential data exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to a WordPress site using the File Upload plugin. This could allow them to manipulate database queries, potentially leading to unauthorized access to sensitive information or disruption of services.

  • No authentication required for access.
  • Triggered via crafted database queries.
  • Risk of unauthorized data access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject malicious SQL queries into the database. This could occur when the vulnerable component is accessible over the network and processes user-supplied input without proper sanitization. The potential impact involves unauthorized access to or modification of database contents.

  • Database contents could be exposed.
  • Unauthenticated network requests could trigger it.
  • Unauthorized database access may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability impacts the WP File Upload plugin for WordPress, a common component in internet-facing web applications. Owners of WordPress sites, potentially supported by infrastructure or platform teams, must first locate all instances of the affected plugin. Prioritize confirmation of business criticality and external reachability for these instances to assess risk, then engage the appropriate team for remediation planning.

  • WordPress site owners should own remediation.
  • Verify plugin instances and business criticality first.
  • Plan remediation based on risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WordPress File Upload plugin?

The WordPress File Upload plugin is a software component designed to enable users to upload files directly through a website's interface. It functions as an extension to the WordPress platform, often used in forms or document management workflows. Because it handles file uploads, it inherently sits as an entry point for user-supplied data on a web server.

How does SQL injection work in CVE-2026-62071?

This vulnerability, classified as CWE-89, occurs when the plugin fails to properly sanitize input before using it in a database query. By sending a specially crafted request, an attacker can manipulate the plugin's interaction with the site's database. This allows them to bypass normal security controls and execute unauthorized SQL commands, potentially exposing or altering the data stored within the application's backend.

Do I need to be logged in to trigger this vulnerability?

No, authentication is not required to exploit this flaw. The vulnerability allows an attacker to interact with the plugin without any prior access or account privileges. It is not triggered by standard site navigation or legitimate file uploads, but rather by malicious, specifically formatted requests designed to inject code into the plugin's database processing functions.

Why is this plugin considered internet-facing?

According to Halo Surface Signal, this plugin is inherently internet-facing because it is designed to accept inputs from public web users. Since the WordPress platform itself is typically hosted for public access, any plugin that processes web requests, like a file uploader, automatically extends that internet-facing surface. This makes the database interaction layer reachable to anyone who can access the site over the network.

How should I respond if I use this plugin?

Your first step is to identify all WordPress instances within your environment that have the File Upload plugin installed. Once identified, evaluate the business criticality of those specific sites to understand the potential impact. Focus your efforts on confirming whether these instances are exposed to the public internet and consult with your technical team to prioritize remediation steps based on your specific risk profile.

References