Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
CVE-2026-66665: WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability — Zero Day Monitor
← Back to list
10.0
CVE-2026-66665
KEV
EXPLOITED
brandexponents · type hub
WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability
Description
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Affected Products
Vendor
Product
Versions
brandexponents
type hub
n/a
References
https://patchstack.com/database/wordpress/plugin/typehub/vulnerability/wordpress-type-hub-plugin-2-0-6-arbitrary-file-upload-vulnerability?_s_id=cve
(vdb-entry)
Related News (1 articles)
Tier C
VulDB
20d ago
CVE-2026-66665 | Brandexponents Type Hub Plugin up to 2.0.6 on WordPress unrestricted upload
→ No new info (linked only)
CVSS 3.1
10.0
CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV
✅ Yes
Actively exploited
✅ Yes
CWE
CWE-434
Published
Aug 6, 2026
Trending Score
6
Source articles
1
Independent
1
Info Completeness
0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack
Community Vote
0
Login to vote
0 upvotes
0 downvotes
No votes yet
Pin to Dashboard
Verification
State:
unverified
Confidence:
0%
Vulnerability Timeline
CVE Published
Aug 6, 2026
Added to CISA KEV
Aug 6, 2026
Actively Exploited
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026