Vulnerabilities & Exploits · Web App Attack

CMS Upload Paths Are Becoming Server Takeovers

File upload features in common CMS plugins are no longer just a way to store content. In this campaign, unauthenticated upload and editor paths are being used to get PHP to run on the server, so a normal-looking upload becomes code execution and site control.

The ACSC says attackers are actively exploiting flaws in Joomla JCE and WordPress plugins including Ninja Forms - File Uploads, Breeze Cache, and WPvivid Backup & Migration. The Joomla issue is already in CISA KEV and past the patch deadline, which confirms this is active abuse, not a theoretical bug report.

The risk reaches beyond the plugin itself. Once a public site can accept and process attacker-controlled uploads as executable code, the full web server and anything it can reach are in play.

2 sources · Jul 13

CVE-2026-48907

NVD KEV

Known exploited · CISA KEV

EPSS 80% (100th percentile).

CISA federal remediation date Jun 19 · date passed

CVE-2026-0740

NVD KEV

CVSS 9.8 CRITICAL: the Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… EPSS 54% (99th percentile).

CVE-2026-3844

NVD KEV

CVSS 9.8 CRITICAL: the Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… EPSS 37% (98th percentile).

CVE-2026-1357

NVD KEV

CVSS 9.8 CRITICAL: the Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. EPSS 33% (98th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-07-12

Every edition of this story: CMS Upload Paths Are Becoming Server Takeovers

More from today