CVE-2026-27067: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27067 is an Unrestricted File Upload vulnerability (CWE-434) in the Syarif Mobile App Editor WordPress plugin that allows authenticated attackers with Editor-level privileges to upload web shells to the web server. All versions up to and including 1.3.1 are affected, and no official patch is currently available. The vulnerability was reported by researcher NumeX on December 12, 2025, and published by Patchstack on March 12, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) (Patchstack).

Technical details

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the plugin fails to properly validate or restrict the file types that authenticated users can upload. An attacker with Editor or Developer-level WordPress privileges can upload a malicious file — such as a PHP web shell — directly to the web server through the plugin's file upload functionality. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (Editor role) to initiate. The changed scope in the CVSS vector indicates that a successful exploit can affect resources beyond the vulnerable plugin itself (Patchstack).

Impact

Successful exploitation allows an attacker to upload and execute arbitrary PHP code (web shells or backdoors) on the web server, resulting in full compromise of confidentiality, integrity, and availability of the affected WordPress site. An attacker can leverage a web shell to exfiltrate sensitive data (database credentials, user data), modify or delete website content, and potentially pivot to other systems on the same hosting environment. The changed scope means the impact extends beyond the WordPress application itself to the underlying server infrastructure (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a currently low probability of near-term exploitation. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No specific threat actor attribution has been reported (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Mobile App Editor plugin (version ≤ 1.3.1) using tools like WPScan, Shodan, or Google dorks targeting plugin-specific paths.
  2. Obtain Editor credentials: Acquire Editor or Developer-level WordPress credentials through phishing, credential stuffing, or brute force against the WordPress login page.
  3. Authenticate: Log in to the WordPress admin dashboard using the obtained credentials.
  4. Locate upload functionality: Navigate to the Mobile App Editor plugin interface and identify the file upload endpoint that lacks proper file type validation.
  5. Craft malicious payload: Prepare a PHP web shell (e.g., a simple <?php system($_GET['cmd']); ?> file saved with a .php extension).
  6. Upload web shell: Submit the malicious PHP file through the plugin's upload feature, bypassing any client-side restrictions.
  7. Execute commands: Access the uploaded web shell via its URL on the server (e.g., https://target.com/wp-content/uploads/shell.php?cmd=id) to execute arbitrary OS commands and achieve full server compromise (Patchstack).

Indicators of compromise

  • File System: Unexpected PHP files (e.g., .php, .phtml, .php5) in WordPress upload directories such as wp-content/uploads/ or plugin-specific directories; files with names resembling web shells (e.g., shell.php, cmd.php, c99.php).
  • Logs: Web server access logs showing POST requests to Mobile App Editor plugin upload endpoints followed by GET requests to newly created PHP files in upload directories; unusual HTTP 200 responses for PHP files in upload directories.
  • Network: Outbound connections from the web server process to unknown external IPs, particularly on non-standard ports; DNS lookups for unfamiliar domains initiated by the web server.
  • Process: Unusual child processes spawned by the web server (e.g., Apache, Nginx, PHP-FPM) such as bash, sh, curl, wget, or python; processes executing system commands with web server user privileges.
  • WordPress Logs: Authentication events for Editor-level accounts followed immediately by plugin file upload activity in WordPress debug or audit logs.

Mitigation and workarounds

As of the disclosure date, no official patch from the plugin vendor (Syarif) is available for versions ≤ 1.3.1. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Recommended actions include: (1) disabling or removing the Mobile App Editor plugin immediately if it is not essential; (2) applying Patchstack's virtual patch if available to your environment; (3) restricting Editor-level user accounts to trusted individuals only; and (4) implementing server-side file upload restrictions (e.g., deny execution of PHP files in upload directories via web server configuration). Monitor the plugin's WordPress.org page and vendor communications for an official patched release (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report covering March 9–15, 2026, highlighting it as part of broader WordPress plugin security concerns (Wordfence Blog). The Hacker Wire published a dedicated article on the vulnerability, describing it as a critical web shell upload risk (The Hacker Wire). Community discussion was noted on Mastodon (infosec.exchange) and Bluesky, with security researchers flagging the lack of an official patch as a concern.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management