Sploitus

CVE-2026-1969

1 known exploit for CVE-2026-1969

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448

Affected products
Trx Addons
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
0.3% (21th percentile)
Weakness
CWE-434
NVD status
Deferred
Published
2026-03-23
CVE-2026-1969 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-1969

Proof-of-concept code and exploit modules indexed by Sploitus