CVE-2026-62071

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.

  • Published Oct 1, 2026
  • CVSS 9.3 critical
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-62071 at the National Vulnerability Database