THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81402 (CRITICAL 9.8) — The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lea

[NVD] CVE-2026-81402 (CRITICAL 9.8) — The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lea

mednvdPublished 2026-09-12

CVE-2026-81402 CVSS: 9.8 CRITICAL Published: 2026-09-12T06:16:25.730

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81402