CVE-2026-5344 | Textpattern up to 4.9.1 XML-RPC rpc/TXP_RPCServer.php mt_uploadImage file.name path traversal (EUVD-2026-18346)
A vulnerability was found in Textpattern up to 4.9.1. It has been classified as critical. Affected by this vulnerability is the function mt_uploadImage of the file rpc/TXP_RPCServer.php of the component XML-RPC Handler. The manipulation of the argument file.name leads to path traversal.
This vulnerability is referenced as CVE-2026-5344. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor confirmed the issue and will provide a fix in the upcoming release.