CVE-2026-1969General

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-03-23); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-06-23: 1Mentions · 2026-07-12: 1Mentions · 2026-07-23: 1Technical Details · 2026-03-23: 103-2303-2406-2307-1207-23
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-231
Disclosure1
2026-03-241
Disclosure1
2026-06-231
General1
2026-07-121
General1
2026-07-231
General1
Full discourse5 posts
  • Rıdvan Yağlı@ridvanyagli
    General

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post lists a set of CVEs reportedly used by attackers against WordPress and Joomla systems, providing no additional technical, exploit, or mitigation information.

    1301142.4K
    2.2K followersView on X
  • Ctrl-Alt-Intel@ctrlaltintel
    General

    Most successful CVEs observed were: CVE-2026-3844 - WP Breeze Cache CVE-2026-1969 - WP ThemeRex (2/n) https://t.co/VvjKXP70se

    Post summary

    The tweet lists two WordPress-related CVEs that were observed to be among the most successful, but it provides no further technical detail, PoC, or exploitation evidence.

    12091564
    1.3K followersView on X
  • Daniel Trojan@dtcz
    General

    Pozor na Wordpress weby... https://www.sentinelone.com/vulnerability-database/cve-2026-1969/ https://t.co/8EFnQWiYZn

    Post summary

    The tweet cautions against WordPress sites linked to CVE‑2026‑1969 but offers no specifics on exploitation, patching, or technical aspects.

    00001700
    4.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1969 🚨 Risk Level: Unknown 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1969 #CVE-2026-1969 #CVE  #Wordpress #CyberSecurity #InfoSec https://t.co/NBJNHfZo9N

    Post summary

    The tweet announces a new CVE-2026-1969 affecting Wordpress, providing only a link to the NVD page without any technical detail, PoC, exploit, or mitigation information.

    0000025
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1969 The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file.… https://www.cve.org/CVERecord?id=CVE-2026-1969

    Post summary

    The CVE-2026-1969 vulnerability in the trx_addons WordPress plugin allows arbitrary file uploads due to improper file‑type validation, with no PoC, exploit, or patch referenced.

    0000059
    56.8K followersView on X

Explore more