THREAT OPS › Threat News › [NVD] CVE-2026-81402 (CRITICAL 9.8) — The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lea
[NVD] CVE-2026-81402 (CRITICAL 9.8) — The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lea
CVE-2026-81402 CVSS: 9.8 CRITICAL Published: 2026-09-12T06:16:25.730
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.
Indicators of compromise
- CVE-2026-81402cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81402