CVE-2026-15282Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-10: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 207-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
Full discourse2 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-15282 — CVSS 9.8/10 ██████████ The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/mhKwQx9jJl

    Post summary

    A critical vulnerability in the Instant Appointment WordPress plugin enables arbitrary file uploads; a patch is available and urged.

    1000071
    65 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: WordPress 3-Plugin File Upload Wave — CVSS 9.8 x2 Super Forms (CVE-2026-14894): Unauthenticated file upload via submit_form Instant Appointment (CVE-2026-15282): Unauthenticated file upload → http://threataft.com/articles/wordpress-plugins-super-forms-instant-appointment-post-export-import-file-upload #cybersecurity #infosec #WordPress

    Post summary

    Two WordPress plugins (Super Forms and Instant Appointment) are disclosed as critically vulnerable to unauthenticated file upload (CVSS 9.8), with no patches or active exploitation reported.

    0000058
    34 followersView on X

Explore more