Critical Remote Code Execution Vulnerabilities in WordPress Plugins Identified

Critical Remote Code Execution Vulnerabilities in WordPress Plugins Identified

First seen 8 Jun 2026, 02:46 UTC CvefeedRadar.OffseqFeedlyLyrie.Aiwww.vulncheck.com+5 90% similarity 69.8

Article Content

Browse articles
ThreatCluster

On June 8, 2026, three critical remote code execution vulnerabilities were disclosed affecting WordPress plugins. CVE-2024-58348 in the Background Image Cropper plugin allows unauthenticated file uploads via the ups.php endpoint, enabling arbitrary code execution. CVE-2023-54350 in the Augmented-Reality plugin also permits file uploads through the elFinder connector, while CVE-2023-54352 in the Seotheme plugin allows PHP code execution via uploaded files in the theme directory. All vulnerabilities have a high CVSS score, indicating severe risk. Currently, no patches are available for CVE-2024-58348, and the other two vulnerabilities are also unpatched. Administrators are advised to disable the affected plugins to mitigate risks. There are no known exploits in the wild at this time.

Key Points: • Three critical RCE vulnerabilities disclosed for WordPress plugins on June 8, 2026. • CVE-2024-58348 allows unauthenticated file uploads via ups.php in Background Image Cropper. • No patches available; disabling affected plugins is recommended for mitigation.

ThreatCluster AI

Timeline

2026-06-08
CVE-2024-58348 published
Critical RCE vulnerability in WordPress Background Image Cropper allows file uploads via ups.php.
Radar.Offseq
2026-06-08
CVE-2023-54350 published
RCE vulnerability in WordPress Augmented-Reality plugin enables file uploads through elFinder connector.
Cvefeed
2026-06-08
CVE-2023-54352 published
RCE vulnerability in WordPress Seotheme allows PHP file uploads to theme directory.
Cvefeed

Community

Browse all →