
🚨 HIGH - Unauthenticated directory traversal in AR for WordPress plugin (CVE-2026-14327) AR for WordPress contains a directory traversal flaw in its file handling logic, where the plugin’s public AJAX functionality accepts a user-controlled 'file' parameter in versions up to 8.40. The root cause is improper input validation/path sanitization, enabling traversal sequences to escape intended directories and target arbitrary server-side files. Attackers can exploit this remotely without authentication by harvesting valid nonces from public AJAX handlers and recreating the plugin’s encryption key locally, which is feasible on default free/unlicensed installs where ar_licence_key is unset. Successful exploitation enables arbitrary file read, exposing secrets like wp-config.php/database credentials, API keys, and other sensitive configuration data that can lead to broader compromise. 👉 Affected: AR for WordPress <= 8.40 | Upgrade to No fix yet — treat as suspicious
Post summary
The post announces an unauthenticated directory traversal flaw in AR for WordPress (CVE‑2026‑14327), detailing the vulnerability mechanism and potential data exposure, but offers no PoC, exploit code, or patch information.
