CVE-2026-1306Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible granted the attacker can obtain a valid nonce. The nonce is exposed in frontend JavaScript making it trivially accessible to unauthenticated attackers.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-14); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-02-14: 5Mentions · 2026-02-15: 2Mentions · 2026-03-24: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-04-28: 1Exploit Tool / Code · 2026-04-28: 1Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-14: 5Technical Details · 2026-02-15: 2Technical Details · 2026-03-24: 102-1402-1503-2404-28
Signal classification3 categories
Disclosure
777.8%
Patch
111.1%
PoC
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-145
Disclosure4Patch1
2026-02-152
Disclosure2
2026-03-241
Disclosure1
2026-04-281
PoC1
Full discourse9 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1306 - critical 🚨 WordPress midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload > WordPress midi-Synth plugin \u003C= 1.1.0 contains an unrestricted file upload vulner... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1306 @pdnuclei #NucleiTemplate...

    Post summary

    The post announces a critical CVE (CVE-2026-1306) for the WordPress midi‑Synth plugin, describing an unauthenticated arbitrary file upload vulnerability, without mentioning any PoC, exploit, patch, or active exploitation.

    00012103
    902 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1306 The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all ve… https://www.cve.org/CVERecord?id=CVE-2026-1306

    Post summary

    The midi-Synth WordPress plugin suffers from an arbitrary file upload flaw caused by missing file type and extension checks in its AJAX export action, as detailed in CVE-2026-1306.

    00010161
    56.5K followersView on X
  • mürrez@murrezsec
    PoC

    WordPress midi-Synth için CVE-2026-1306 (≤1.1.0) çoklu hedef PoC / liste runner — expose olan midiSynth_nonce + export AJAX http://github.com/murrez/CVE-2026-1306

    Post summary

    The post announces a Proof of Concept for CVE-2026-1306 that exploits WordPress midi‑Synth via the midiSynth_nonce and export AJAX endpoints, with the code hosted on GitHub.

    0000080
    591 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1306: midi-Synth <= 1.1.0 - Unauthentic... Exposed nonces + zero file validation in midi-Synth's AJAX handler creates trivial RCE path for unauthenticated attacker... https://zerodaysignal.com/vulnerability/CVE-2026-1306 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new CVE (CVE-2026-1306) affecting midi‑Synth <= 1.1.0 is disclosed, revealing nonce exposure and zero file validation that allow a trivial RCE for unauthenticated users. No exploit code or patch is referenced, and no active exploitation is reported.

    0000047
    131 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: WordPress midi-Synth plugin (all versions ≤1.1.0) lets unauthenticated attackers upload dangerous files — risk of RCE! Disable plugin or apply mitigations ASAP. https://radar.offseq.com/threat/cve-2026-1306-cwe-434-unrestricted-upload-of-file--95798a0f #OffSeq #Wor... https://t.co/5iYznZJLrs

    Post summary

    The tweet announces a critical WordPress midi‑Synth plugin flaw that permits unauthenticated file uploads and potential remote code execution, urging users to disable the plugin or apply mitigations.

    0000043
    265 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1306 Unauthenticated Arbitrary File Upload Vulnerability in WordPress midi-Synth Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1306

    Post summary

    A brief disclosure notes an unauthenticated arbitrary file upload flaw in the WordPress midi‑Synth plugin (CVE‑2026‑1306) with no PoC, exploit, or mitigation details.

    0000031
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1306: CRITICAL] WordPress midi-Synth plugin &lt;= 1.1.0 is vulnerable to arbitrary file uploads, allowing unauthenticated attackers to execute remote code by exploiting missing file validation in the 'e...#cve,CVE-2026-1306,#cybersecurity https://cvefind.com/CVE-2026-1306

    Post summary

    WordPress midi‑Synth plugin versions <=1.1.0 are critically vulnerable to arbitrary file uploads that enable unauthenticated remote code execution due to missing validation. No PoC, exploit code, or patch information is provided.

    0000069
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1306 - Critical The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and in... https://www.thehackerwire.com/vulnerability/CVE-2026-1306/ https://t.co/jyKsHze3nt

    Post summary

    The tweet announces the disclosure of CVE-2026-1306, detailing an arbitrary file upload vulnerability in the midi‑Synth WordPress plugin, and provides a link to further information.

    0000092
    112 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 Critical flaw in adminkov midi-Synth for WordPress (CVE-2026-1306): Unauthenticated file uploads can lead to RCE. Immediate action: update or disable plugin, monitor uploads! Details: https://radar.offseq.com/threat/cve-2026-1306-cwe-434-unrestricted-upload-of-file--95798a0f... https://t.co/QaNG0Tz38v

    Post summary

    The ad mentions a critical flaw in the adminkov midi‑Synth WordPress plugin (CVE‑2026‑1306) that allows unauthenticated file uploads leading to remote code execution; users are urged to update or disable the plugin immediately.

    0000066
    268 followersView on X

Explore more