CVE-2026-81090
Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
| Vendor | unknown |
| Product | gpx2graphics |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown gpx2graphics
Be the first to know when new high vulnerabilities affecting unknown gpx2graphics are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Gpx2Graphics
0 โค 0.3
References
Credits
Huynh Kien Minh WPScan