WordPress midi-Synth plugin \u003C= 1.1.0 contains an unrestricted file upload vulnerability caused by missing file type and extension validation in the 'export' AJAX action, letting unauthenticated attackers upload arbitrary files and potentially execute remote code, exploit requires attacker to obtain a valid nonce exposed in frontend JavaScript.
id: CVE-2026-1306
info:
name: WordPress midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Uplo
...