What the vulnerability does
01Description
HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution.
Explanation of Vulnerability in Simple Terms
02Summary
HS Brand Logo Slider contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary files to the server. An attacker with low-level site access can upload malicious files, potentially gaining the ability to run code on the site. This affects version 2.1 and requires an active site account to exploit.
What an attacker can do
03Attacker Capabilities
Upload arbitrary files to the server and potentially execute code on the site.
Potential impact on your site
04Site Impact
A compromised or malicious user account can upload files that compromise your entire site.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
May 16, 2026
CVE published
May 18, 2026
Record updated