CVE-2026-48907
Known exploited · CISA KEV
EPSS 80% (100th percentile).
CISA federal remediation date Jun 19 · date passed
Vulnerabilities & Exploits · Web App Attack
File upload features in common CMS plugins are no longer just a way to store content. In this campaign, unauthenticated upload and editor paths are being used to get PHP to run on the server, so a normal-looking upload becomes code execution and site control.
The ACSC says attackers are actively exploiting flaws in Joomla JCE and WordPress plugins including Ninja Forms - File Uploads, Breeze Cache, and WPvivid Backup & Migration. The Joomla issue is already in CISA KEV and past the patch deadline, which confirms this is active abuse, not a theoretical bug report.
The risk reaches beyond the plugin itself. Once a public site can accept and process attacker-controlled uploads as executable code, the full web server and anything it can reach are in play.
2 sources · Jul 13
Known exploited · CISA KEV
EPSS 80% (100th percentile).
CISA federal remediation date Jun 19 · date passed
CVSS 9.8 CRITICAL: the Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… EPSS 54% (99th percentile).
CVSS 9.8 CRITICAL: the Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… EPSS 37% (98th percentile).
CVSS 9.8 CRITICAL: the Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. EPSS 33% (98th percentile).
Infosecurity Magazine
Australian Cyber Agency Warns of Global CMS Exploitation Campaign
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
originalBleepingComputer
Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins.
originalPart of the PlainSec briefing for 2026-07-13
Every edition of this story: CMS Upload Paths Are Becoming Server Takeovers