
CVE-2026-12872 The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or… https://www.cve.org/CVERecord?id=CVE-2026-12872
Post summary
The Webinfos WordPress plugin allows unrestricted file uploads because it does not validate file types or names, indicating a significant vulnerability.

