Executive brief
The WHMCS Bridge plugin for WordPress, which integrates billing and support services into websites, contains a security flaw that allows users with low-level account access to upload malicious files. An attacker could use this to take full control of the website's server, potentially leading to data theft or a complete service shutdown. This affects all versions of the plugin up to and including 6.9.
Technical details
The WHMCS Bridge plugin for WordPress is vulnerable to unrestricted file uploads (CWE-434) due to a lack of file type validation within the connect() function. Authenticated attackers with 'Custom-level' permissions or higher can exploit this flaw via a network request to upload executable files, such as PHP scripts, to the server. This vulnerability can lead to remote code execution (RCE) and full system compromise. The issue is present in all versions up to and including 6.9; users should check for updates from the vendor.
Affected products
- globalprogramming WHMCS Bridge <= 6.9
Timeline
- 2026-07-08: disclosed: Initial disclosure by Wordfence and NVD publication.
References
- https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/bridge.init.php
- https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/bridge.init.php
- https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/bridge.init.php
- https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/includes/request.class.php
- https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/includes/request.class.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c4fe6dcc-93c8-4956-85ae-a1125bc84509?source=cve