Junglewise Threat Intelligence

CVE-2026-32559: UltimateAI arbitrary file upload in subscriber upload handler

CVE-2026-32559 · Severity: critical · CVSS 9.9 · Published 2026-08-24

Executive brief

UltimateAI is a WordPress plugin that extends site functionality with AI-powered features. The plugin contains an arbitrary file upload vulnerability that allows authenticated subscribers to upload malicious files to the server, potentially enabling complete server compromise and website takeover.

Technical details

The vulnerability is an arbitrary file upload flaw in UltimateAI versions 3.1.0 and earlier, exploitable by authenticated users with subscriber-level privileges. The plugin fails to properly validate or restrict uploaded file types and locations, allowing attackers to upload arbitrary files (such as PHP webshells) to the server. No special privileges beyond basic subscriber access are required. Successful exploitation permits remote code execution and full server compromise. No official patch was available at the time of disclosure on August 24, 2026.

Affected products

  • UltimateAI UltimateAI <=3.1.0

Timeline

  • 2026-08-24: disclosed: Vulnerability disclosed by Jamaal ahmed
  • 2026-06-28: other: Vulnerability reported to Patchstack

References