peter bassill · operator
$ cve CVE-2026-1306 JSON

CVE-2026-1306

9.8
CRITICAL · CVSS 3.1 · EPSS 4.6% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible granted the attacker can obtain a valid nonce. The nonce is exposed in frontend JavaScript making it trivially accessible to unauthenticated attackers.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.56% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2026-02-14
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD