HomeSecurityVulnerability in W CMS allows code execution via file upload

Vulnerability in W CMS allows code execution via file upload

Two new vulnerability listings concern W CMS, a content management system developed by Vincent Peugnet. The most severe, CVE-2026-105123, is rated 8.7 on the CVSS-B scale and describes a way for a registered author to store arbitrary files on the server, potentially executing code, according to the NVD listing. A second listing concerns stored XSS without requiring a login.

code execution via file upload

The entry for CVE-2026-105123 is attributed to VulnCheck and covers W CMS versions up to 3.18.0. According to the NVD database, the vulnerability has a CVSS-B score of 8.7 and is classified as CWE-434, which is insufficient restriction of dangerous file uploads. The entry does not name a patched version.

The description refers to the Media Upload API and a path that is not adequately checked. A connected author could, according to the technical description of CVE-2026-105123, bypass the intended media folder and store a PHP file in a location where the server executes it. The result could be code execution with the privileges of the web service.

How code execution occurs in W CMS

The problem is with handling the path given in the request to the API, not just accepting a regular image file. The entry describes encoded top-level elements, such as "../", which can lead outside the upload folder. If the website stores an executable file in a location that is served directly, code execution can occur from a remote request.

The access required for the first vulnerability is an author account in W CMS. This narrows the circle of potential attackers relative to a no-login bug, but does not eliminate the risk: lower-privileged accounts can be compromised or misused. The NVD assessment reports a network vector and low attack complexity.

Meanwhile, CVE-2026-105124 describes a stored XSS that, according to the corresponding NVD entry, can be injected with an alias on a failed login attempt or with the website address in a comment. The content is reported to be displayed without safe escape in the admin logs or in a comment link. NVD records a CVSS-B score of 5.3, while the CVE entry states that user interaction is required to execute the script.

impact on CMS server

The two records should not be confused with a confirmed online exploit. The available records describe technical implications, but do not document that attackers are already exploiting the vulnerabilities in real-world attacks. Also, CVE-2026-105123 requires an author account, while the XSS in CVE-2026-105124 can be initiated by an unlogged visitor, provided that the affected content is opened.

See also: Critical vulnerability in WooCommerce Wholesale Lead Capture

The investigator's report remains open

In the project repository, researcher Ikram-4 opened issue #662 on October 2, describing multiple security issues in version 3.18.0, including executable file uploads, non-directory paths, and XSS. The issue remains open, and its page shows no response from the maintainer.

The latest published version listed in the repository is 3.18.0, while VulnCheck's entry includes it among the affected versions. The release notes mention changes to the installation wizard, but do not name a fix for the specific vulnerabilities. Thus, there is currently no documented release available that fixes the two issues.

See also: New CVE allows remote bypass in lin-cms-spring-boot

management access restriction

Temporary measures until a correction is made

Administrators using W CMS need to check the version and monitor the release repository for an official fix. Upgrading to 3.18.0 alone is not enough, as this version is within the scope of VulnCheck. There is no documented newer fix release in the sources reviewed.

Until a fixed version is published, the SecNews technical team recommends restricting access to the admin page to authorized networks and re-verifying editor accounts. Where possible, administrators can temporarily disable public comments and check the logs and upload folder for unusual files.

Temporary fixes reduce exposure, but are not a substitute for a fix to the code. As the core finding concerns file paths and allowed upload types, a meaningful fix depends on a fix and clear confirmation of the version by the maintainer.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Vulnerability in Elementor Pro is used in cyberattacks

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS