{"id":"CVE-2026-9227","summary":"GutenBee \u003c= 2.20.1 - Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter","details":"The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames like shell.json.php to bypass validation. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible.","modified":"2026-08-07T11:48:25.667311158Z","published":"2026-05-28T06:45:39.874Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9227.json","cna_assigner":"Wordfence","cwe_ids":["CWE-434"]},"references":[{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/gutenbee/tags/2.20.0/gutenbee.php#L570"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/gutenbee/tags/2.20.0/gutenbee.php#L571"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/gutenbee/tags/2.20.0/gutenbee.php#L579"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/gutenbee/tags/2.20.1/gutenbee.php#L570"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/gutenbee/tags/2.20.1/gutenbee.php#L571"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/gutenbee/tags/2.20.1/gutenbee.php#L579"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3543574%40gutenbee&new=3543574%40gutenbee&sfp_email=&sfph_mail="},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d20e8c9-975d-4e8c-8bea-50935853c7d4?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9227.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9227"},{"type":"FIX","url":"https://github.com/cssigniter/gutenbee/commit/bde934cdecf67a4de1d6548cc1fc6c59bc6690e5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cssigniter/gutenbee","events":[{"introduced":"0"},{"fixed":"bde934cdecf67a4de1d6548cc1fc6c59bc6690e5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.20.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.20.1","2.20.0","2.19.1","2.19.0","2.18.1","2.18.0","2.17.4","2.17.3","2.17.2","2.17.1","2.17.0","2.16.1","2.16.0","2.15.0","2.14.0","2.13.1","2.13.0","2.12.5","2.12.4","2.12.3","2.12.2","2.12.1","2.12.0","2.11.1","2.11.0","2.10.6","2.10.5","2.10.4","2.10.3","2.10.2","2.10.1","2.10.0","2.9.0","2.8.1","2.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9227.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}