Vulnerability Description
The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code execution. This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation.
CVSS Score
HIGH
References
FAQ
What is CVE-2026-11962?
CVE-2026-11962 is a vulnerability with a CVSS score of 8.8 (HIGH). The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — ...
How severe is CVE-2026-11962?
CVE-2026-11962 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11962?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.