
CVE-2026-4808 The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUploadedFile() functio… https://www.cve.org/CVERecord?id=CVE-2026-4808
Post summary
The post announces CVE‑2026‑4808, a vulnerability in the Gerador de Certificados – DevApps WordPress plugin that allows arbitrary file uploads due to missing file type validation.
