GHSA-r3hg-hgx7-58g9HighCVSS 8.8

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that...

Published
October 4, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (1)

📋 Description

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[:path].

🔗 References (7)