CVE-2026-66665

Brandexponents · Type Hub

An unauthenticated arbitrary file upload vulnerability exists in the Brandexponents Type Hub plugin for WordPress, allowing remote code execution.

Executive summary

A critical unauthenticated arbitrary file upload vulnerability in the Brandexponents Type Hub plugin allows attackers to achieve remote code execution on the underlying server.

Vulnerability

The plugin contains an unrestricted file upload mechanism that does not require authentication, allowing attackers to upload malicious files such as web shells. This vulnerability is remotely exploitable without user interaction, as indicated by the CVSS vector.

Business impact

An arbitrary file upload vulnerability is considered a critical security failure, as it typically leads to full system compromise. With a CVSS score of 10.0, this flaw allows attackers to gain persistent access to the server, steal sensitive data, or pivot to internal network resources, posing an extreme risk to business operations.

Remediation

Immediate Action: Disable or uninstall the Type Hub plugin immediately until a patched version is confirmed and applied.

Proactive Monitoring: Inspect the web server upload directories for recently created executable files, such as PHP scripts, that deviate from expected file types.

Compensating Controls: Ensure the web server process has restricted write permissions to only necessary directories and verify that direct execution of files in upload folders is disabled at the web server configuration level.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The 10.0 CVSS score and the nature of the vulnerability demand immediate attention. Organizations currently running the Type Hub plugin must remove the software from their environment until a verified security update is deployed to prevent potential server takeover.