Junglewise Threat Intelligence

CVE-2026-4808: DevApps Gerador de Certificados arbitrary file upload in moveUploadedFile

CVE-2026-4808 · Severity: high · CVSS 7.2 · Published 2026-04-08

Executive brief

The Gerador de Certificados – DevApps plugin for WordPress, which is used to generate certificates, contains a security flaw that allows high-level users to upload restricted file types. An attacker with administrative credentials could exploit this to upload malicious scripts to the web server. This could lead to a complete takeover of the website and its underlying server, potentially exposing sensitive data or disrupting operations.

Technical details

The vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434) within the moveUploadedFile() function of the Gerador de Certificados – DevApps plugin. The root cause is a lack of file type validation, allowing any file extension to be processed and stored on the server. While the attack requires Administrator-level privileges, it provides a path for remote code execution (RCE) by uploading PHP scripts. The issue affects all versions up to and including 1.3.6; users should check for updates or patches from the vendor.

Affected products

  • tidevapps Gerador de Certificados – DevApps <= 1.3.6

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References