
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27067 is an Unrestricted File Upload vulnerability (CWE-434) in the Syarif Mobile App Editor WordPress plugin that allows authenticated attackers with Editor-level privileges to upload web shells to the web server. All versions up to and including 1.3.1 are affected, and no official patch is currently available. The vulnerability was reported by researcher NumeX on December 12, 2025, and published by Patchstack on March 12, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) (Patchstack).
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the plugin fails to properly validate or restrict the file types that authenticated users can upload. An attacker with Editor or Developer-level WordPress privileges can upload a malicious file — such as a PHP web shell — directly to the web server through the plugin's file upload functionality. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (Editor role) to initiate. The changed scope in the CVSS vector indicates that a successful exploit can affect resources beyond the vulnerable plugin itself (Patchstack).
Successful exploitation allows an attacker to upload and execute arbitrary PHP code (web shells or backdoors) on the web server, resulting in full compromise of confidentiality, integrity, and availability of the affected WordPress site. An attacker can leverage a web shell to exfiltrate sensitive data (database credentials, user data), modify or delete website content, and potentially pivot to other systems on the same hosting environment. The changed scope means the impact extends beyond the WordPress application itself to the underlying server infrastructure (Patchstack).
No public proof-of-concept exploit code has been identified at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a currently low probability of near-term exploitation. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No specific threat actor attribution has been reported (Patchstack).
<?php system($_GET['cmd']); ?> file saved with a .php extension).https://target.com/wp-content/uploads/shell.php?cmd=id) to execute arbitrary OS commands and achieve full server compromise (Patchstack)..php, .phtml, .php5) in WordPress upload directories such as wp-content/uploads/ or plugin-specific directories; files with names resembling web shells (e.g., shell.php, cmd.php, c99.php).bash, sh, curl, wget, or python; processes executing system commands with web server user privileges.As of the disclosure date, no official patch from the plugin vendor (Syarif) is available for versions ≤ 1.3.1. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Recommended actions include: (1) disabling or removing the Mobile App Editor plugin immediately if it is not essential; (2) applying Patchstack's virtual patch if available to your environment; (3) restricting Editor-level user accounts to trusted individuals only; and (4) implementing server-side file upload restrictions (e.g., deny execution of PHP files in upload directories via web server configuration). Monitor the plugin's WordPress.org page and vendor communications for an official patched release (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report covering March 9–15, 2026, highlighting it as part of broader WordPress plugin security concerns (Wordfence Blog). The Hacker Wire published a dedicated article on the vulnerability, describing it as a critical web shell upload risk (The Hacker Wire). Community discussion was noted on Mastodon (infosec.exchange) and Bluesky, with security researchers flagging the lack of an official patch as a concern.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."