Executive brief
The Sync Post With Other Site WordPress plugin allows users with contributor-level permissions to upload arbitrary files to a website. An attacker with a contributor account (or anyone who can create one) can exploit this to upload malicious code, potentially gaining full control over the website and the server it runs on. This could lead to data theft, site defacement, malware distribution, or complete service outage.
Technical details
This vulnerability is an arbitrary file upload vulnerability in the Sync Post With Other Site WordPress plugin affecting versions 1.9.3 and earlier. The plugin fails to properly validate file types during upload operations, allowing authenticated users with contributor privileges to upload executable files. Exploitation requires contributor-level access or higher, but no network authentication bypass is needed once a valid contributor account exists. An attacker can upload malicious PHP or other executable code, which can then be executed to achieve remote code execution on the affected server. As of the publication date, no official patch is available, though mitigation rules have been issued.
Affected products
- WordPress Sync Post With Other Site <=1.9.3
Timeline
- 2026-08-18: disclosed: CVE-2026-32463 published on NVD
- 2026-08-17: advisory: Patchstack security advisory issued