CVE-2026-4882Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a "Profile Picture" field is added to the form.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-05-02); latest day: 4
  • 12 total mentions across 5 days

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-05-02: 5Mentions · 2026-05-07: 1Mentions · 2026-05-09: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 4Patch / Workaround · 2026-05-02: 3Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-02: 5Technical Details · 2026-05-09: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 305-0205-0705-0905-1305-14
Signal classification3 categories
Disclosure
650.0%
Patch
433.3%
General
216.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-025
Disclosure2Patch3
2026-05-071
General1
2026-05-091
Disclosure1
2026-05-131
Patch1
2026-05-144
Disclosure3General1
Full discourse12 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 تنبيه لأصحاب مواقع ومدونات (WordPress) إذا تستخدم أي من هذي الإضافات، حدثها فوراً! لأنها مصابة بثغرات حرجة جداً بتقييم (CVSS: 9.8). الإضافات المصابة: 1️⃣ إضافة (Temporary Login) | الثغرة: CVE-2026-7567 2️⃣ إضافة (User Registration) | الثغرة: CVE-2026-4882 3️⃣ إضافة (User Verification) | الثغرة: CVE-2026-7458

    Post summary

    The post alerts WordPress administrators about several plugins containing critical CVEs (CVSS 9.8) and urges them to apply patches immediately.

    1301482.5K
    49.3K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4882 — CVSS 9.8/10 ██████████ The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/IyBV4VxqlH

    Post summary

    The tweet announces CVE-2026-4882, a critical arbitrary file upload flaw in a WordPress plugin, and urges users to apply the available patch.

    1001174
    26 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-4882 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑4882 with critical severity (CVSS 9.8/3.1) but offers no information on exploitation, tools, or remediation.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-4882 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the…

    Post summary

    A critical advisory for CVE-2026-4882 highlights an arbitrary file upload flaw due to missing file type validation in the User Registration Advanced Fields WordPress plugin.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-4882 (CVSS 9.8) — multiple products. CVE: CVE-2026-4882 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces a critical vulnerability (CVE-2026-4882) with CVSS 9.8 but provides no evidence of exploitation, PoC, or patch information.

    1000027
    210 followersView on X
  • SwissWPSecure@Swisswpsecure
    Disclosure

    Same day: CVE-2026-4882. Also CVSS 9.8. A registration plugin lets unauthenticated attackers upload PHP files through profile picture fields. No validation. No login. The server executes the file. Two critical flaws. One day. Both: zero credentials needed.

    Post summary

    The text discloses CVE‑2026‑4882, noting a CVSS of 9.8 and describing an unauthenticated file‑upload RCE flaw in a plugin, without mentioning active exploitation, patches, or a PoC.

    0001048
    1 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-4882-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The snippet merely links to a CVE advisory and includes hashtags; it does not provide detailed information about the vulnerability or related exploits, patches, or active exploitation.

    0000015
    210 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A high-severity vulnerability (CVE-2026-4882) affects the User Registration Advanced Fields WordPress plugin, allowing arbitrary file uploads if a "Profile Picture" field is used. Update or patch promptly to reduce risk of remote code execution. #cybersecurity

    Post summary

    The post warns of a high‑severity flaw in the User Registration Advanced Fields WordPress plugin that permits arbitrary file uploads via a profile picture field, recommending users update or patch the plugin immediately to mitigate a remote code execution risk.

    0000045
    80 followersView on X
  • くりとグラの聴くサイバー防衛ラジオ@KuriGCyberRadio
    General

    https://youtu.be/kZxQZcwLR00 - Apache HTTP/2の重大な脆弱性(CVE-2026-23918) - DAEMON Toolsのサプライチェーン攻撃 - WordPressのUser Registration Advanced Fieldsプラグイン脆弱性(CVE-2026-4882) の3本でお送りします。

    Post summary

    The video merely lists three CVEs (including Apache HTTP/2, DAEMON Tools supply‑chain, and a WordPress plugin) without providing exploitation, patch, or technical details.

    00000122
    2 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    ⚠️ CVE-2026-4882: WordPress plugin vulnerability lets attackers upload arbitrary files. Urgent: Patch to version 1.6.21 now to prevent unauthorized access. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #Linux #WordPress https://t.co/u3RozJ50zE

    Post summary

    The tweet alerts to CVE‑2026‑4882, a WordPress plugin flaw allowing arbitrary file uploads, and urges users to patch to version 1.6.21, with no mention of active exploitation or PoC.

    0000048
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4882 Arbitrary File Upload Vulnerability in User Registration Advanced ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4882 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post simply announces CVE‑2026‑4882 with a brief reference to an arbitrary file upload flaw and links to advisory pages, offering no detailed exploitation or mitigation information.

    0000047
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-4882 The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-4882 #WordPress #CyberSecurity #InfoSec

    Post summary

    A critical CVE (CVE‑2026‑4882) affecting the WordPress User Registration Advanced Fields plugin has been disclosed, featuring an arbitrary file upload flaw (CVSS 9.8) with no patch available yet; a full analysis link is provided but no PoC or exploit details are shared.

    0000052
    458 followersView on X

Explore more