CVE-2026-14327Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires an attacker to first obtain a valid nonce and secure nonce via the publicly accessible ar_get_fresh_nonce and ar_process_user_image nopriv AJAX handlers, and to reproduce the encryption key locally — both steps are fully achievable by an unauthenticated attacker on any default free or unlicensed installation where ar_licence_key is unset.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-03: 1Technical Details · 2026-07-03: 107-03
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Unauthenticated directory traversal in AR for WordPress plugin (CVE-2026-14327) AR for WordPress contains a directory traversal flaw in its file handling logic, where the plugin’s public AJAX functionality accepts a user-controlled 'file' parameter in versions up to 8.40. The root cause is improper input validation/path sanitization, enabling traversal sequences to escape intended directories and target arbitrary server-side files. Attackers can exploit this remotely without authentication by harvesting valid nonces from public AJAX handlers and recreating the plugin’s encryption key locally, which is feasible on default free/unlicensed installs where ar_licence_key is unset. Successful exploitation enables arbitrary file read, exposing secrets like wp-config.php/database credentials, API keys, and other sensitive configuration data that can lead to broader compromise. 👉 Affected: AR for WordPress <= 8.40 | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post announces an unauthenticated directory traversal flaw in AR for WordPress (CVE‑2026‑14327), detailing the vulnerability mechanism and potential data exposure, but offers no PoC, exploit code, or patch information.

    00000113
    236 followersView on X

Explore more