CVE-2026-1555Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-15); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-15: 2Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-30: 1PoC Mentioned / Linked · 2026-04-18: 1Exploit Tool / Code · 2026-04-18: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-17: 1Technical Details · 2026-04-30: 104-1504-1704-1804-30
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure2
2026-04-171
Disclosure1
2026-04-181
PoC1
2026-04-301
Patch1
Full discourse5 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🌐 مدونة WordPress : 🪗 إضافة Accordion Slider (الأخطر): التقييم: 9.8 | (CVE-2026-6443) ⚠️عبارة عن Backdoor مزروع عمداً في الإصدار (1.4.6). 🧩 إضافات أخرى (بتقييم 9.8): ⚠️ تسمح برفع ملفات وتخطي المصادقة في الإضافات التالية: 📂 إضافة WebStack برقم (CVE-2026-1555) 💳 إضافة Visa Plugin برقم (CVE-2026-3461) 🔀 إضافة Barcode Scanner برقم (CVE-2026-4880)

    Post summary

    The text highlights that WordPress plugin Accordion Slider v1.4.6 contains a purposely planted backdoor, and other plugins allow file upload and authentication bypass, indicating new high‑severity vulnerabilities.

    110021.3K
    48.7K followersView on X
  • Nxploited@Nxploited
    PoC

    VE-2026-1555 — WebStack WordPress Arbitrary File Upload PoC: https://github.com/Nxploited/CVE-2026-1555 #hacker #Cybersécurité #exploit #CVEs #CVE

    Post summary

    The post announces CVE-2026-1555 (WebStack WordPress Arbitrary File Upload) and provides a link to a PoC demonstrating the flaw, without any evidence of active exploitation, patches, or detailed technical description.

    00020146
    96 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-1555: Critical #WordPress Vulnerability A newly disclosed flaw exposes applications to unauthenticated exploitation, potentially leading to remote code execution and full system compromise. https://nvd.nist.gov/vuln/detail/CVE-2026-1555 What’s the risk? 👉 Attackers can execute arbitrary code remotely 👉 Full site takeover & backend access 👉 Malware injection, webshells & persistent backdoors 👉 Data breaches, downtime & revenue loss Root cause Improper input validation / insecure handling of user-controlled data — still one of the most exploited weaknesses. Why this matters ⚠️ Low attack complexity ⚠️ High impact across web apps & CMS platforms ⚠️ Easily weaponized in automated attacks How to protect your site ✅ Apply patches immediately ✅ Sanitize and validate all inputs ✅ Monitor file & behavior anomalies ✅ Deploy full perimeter security scanning #CVE #CyberSecurity #Infosec #WebSecurity #Malware #WooCommerce #SilentRisk

    Post summary

    The tweet highlights a newly disclosed WordPress vulnerability, emphasizing the need for immediate patching and basic mitigations, while detailing its high impact and low attack complexity. It does not provide proof‑of‑concepts or evidence of active exploitation.

    1000032
    40 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1555 The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and … https://www.cve.org/CVERecord?id=CVE-2026-1555

    Post summary

    The post announces CVE‑2026‑1555, indicating that the WebStack WordPress theme allows arbitrary file uploads because of missing file type validation.

    0000059
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1555: WebStack <= 1.2024 - Unauthentica... No-auth file upload in WebStack's io_img_upload() function = instant webshells for script kiddies - WordPress sites runn... https://zerodaysignal.com/vulnerability/CVE-2026-1555 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-1555, describing an unauthenticated file upload flaw that could enable webshells on WebStack sites, but it does not provide a PoC, exploit code, or patch information.

    0000078
    218 followersView on X

Explore more