CVE-2026-28133 HIGH

CVE-2026-28133: WordPress Filr plugin <= 1.2.14 - Arbitrary File Upload vulnerability

Vendor Wp Chill
Product Filr
Weakness CWE-434 · Unrestricted file upload
Published March 5, 2026
Last update April 28, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.

Explanation of Vulnerability in Simple Terms

02Summary

WP Chill Filr versions up to 1.2.14 do not properly validate uploaded files, allowing authenticated users to upload malicious files that can compromise the site. An attacker with low-level access can upload files without restriction, potentially executing code or modifying site content. The vulnerability affects multiple security properties and may impact systems beyond the vulnerable component.

What an attacker can do

03Attacker Capabilities

Upload files without validation and execute code or modify site data.

Potential impact on your site

04Site Impact

Compromised site integrity, data theft, and potential code execution by authenticated attackers.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account; no user interaction required.

Key dates

06Disclosure timeline

March 5, 2026 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE