
🚨 CVE-2026-3335 - medium 🚨 Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload > The Canto plugin for WordPress is vulnerable to missing authorization in the copy-med... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3335 @pdnuclei #NucleiTemplates ...
Post summary
The tweet announces CVE-2026-3335 as a medium‑severity vulnerability in the Canto WordPress plugin, describing a missing authorization flaw that allows unauthenticated file uploads. It provides basic technical details but no PoC, exploit code, patch information, or evidence of active exploitation.


