plugin

Midi Synth Vulnerabilities

1 known security issue reported for the Midi Synth WordPress plugin. Most recent disclosed Feb 13, 2026.

1 critical

Running Midi Synth on your site? Check whether your installed version is affected.

Scan your site free

midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action

critical

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which m...

CVSS:
9.8
Affected:
up to 1.1.0
Fixed in:
2.0.0
Disclosed:
Feb 13, 2026

CVE-2026-1306 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database