HIGH
lightsyncpro
CVE published 2026-08-05
CVE-2026-6147
The LightSync Pro plugin for WordPress, specifically versions up to and including 2.1.6, is vulnerable to arbitrary file uploads. This vulnerability stems from missing file type validation in the rest_replace_media() function, allowing authenticated attackers with Author-level access and above to upload arbitrary files on the affected site's server. Such uploads may lead to remote code execution, posing a [truncated]