CVE-2026-1730Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-03: 4Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 402-03
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1730 Authenticated Arbitrary File Upload Vulnerability in OS DataHub Maps WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1730

    Post summary

    A new authenticated arbitrary file upload vulnerability (CVE‑2026‑1730) has been identified in the OS DataHub Maps WordPress plugin. The advisory provides basic technical details but does not mention exploitation, PoC, patches, or active attacks.

    0000058
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1730: HIGH] Critical vulnerability in OS DataHub Maps plugin for WordPress allows authenticated attackers to upload arbitrary files due to incorrect validation. Update to version 1.8.4 now.#cve,CVE-2026-1730,#cybersecurity https://cvefind.com/CVE-2026-1730

    Post summary

    The post highlights CVE-2026-1730, a critical WordPress plugin flaw that permits authenticated file uploads, and urges users to upgrade to version 1.8.4.

    0000061
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1730 - High The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions... https://www.thehackerwire.com/vulnerability/CVE-2026-1730/ https://t.co/l6KpAxqqjb

    Post summary

    The post announces CVE‑2026‑1730, revealing that the OS DataHub Maps WordPress plugin allows arbitrary file uploads because of improper file type validation.

    0000054
    113 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1730 The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' … https://www.cve.org/CVERecord?id=CVE-2026-1730

    Post summary

    The OS DataHub Maps WordPress plugin is susceptible to arbitrary file uploads caused by improper file type validation, as reported in CVE-2026-1730.

    00000216
    56.5K followersView on X

Explore more