Textpattern versions prior to 4.8.3 contain an...
High severity
Unreviewed
Published
Jan 23, 2026
to the GitHub Advisory Database
•
Updated Jan 23, 2026
Description
Published by the National Vulnerability Database
Jan 23, 2026
Published to the GitHub Advisory Database
Jan 23, 2026
Last updated
Jan 23, 2026
Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.
References