CVE-2026-81090 PUBLISHED

Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF

Assigner: WPScan
Reserved: 26.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.

Product Status

Vendor Unknown
Product Gpx2Graphics
Versions Default: unknown
  • affected from 0 to 0.3 (incl.)

Credits

  • Huynh Kien Minh finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE