CVE-2026-14553
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.
| Vendor | unknown |
| Product | zportals |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown zportals
Be the first to know when new unknown vulnerabilities affecting unknown zportals are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / zportals
0 < 6.3.4
References
Credits
Mike Gozdiskowski WPScan