CVE-2026-27064

WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.


We have discovered 1,486 live websites that are affected by CVE-2026-27064.

Run a Free Instant Scan




Affected Software

Product  Mailster
Category Wordpress Plugins
Vulnerable Domains1,486 live websites (100% of Mailster install base)
Vulnerable Versions
  • from 0 through 4.1.17
Vulnerable Versions Count100 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Phat RiO | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-27064
United States269 websites



Germany255 websites
Italy220 websites
France75 websites
Hungary58 websites
Spain48 websites
Poland45 websites
Austria37 websites
Brazil37 websites
Switzerland34 websites

Website Distribution by TLD

Number of websites using CVE-2026-27064
.com520 websites
.de140 websites
.it118 websites
.org62 websites
.at45 websites
.com.br37 websites
.pl36 websites
.ch34 websites
.eu28 websites
.net26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-27064

Top websites that are affected by CVE-2026-27064. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com Bulgaria**,***
********************.org Germany***,***
*********.com United States***,***
***.***.tr Turkey***,***
***********.com United States***,***
********.org Italy***,***
********.com Lithuania***,***
*************.com Germany***,***
************.org Germany***,***
*****************.***.uk GB***,***
See full domain list

FAQ

CVE-2026-27064 is Unrestricted Upload of File with Dangerous Type in Mailster
A total of 1,486 websites have been identified as vulnerable to CVE-2026-27064, based on global website indexing conducted by WebTechSurvey.
The Mailster is affected by the CVE-2026-27064 vulnerability.
Mailster versions up to and including 4.1.17 are vulnerable to CVE-2026-27064.