CVE · Medium

CVE-2026-11426 — Under Construction [under-construction-page] < 5.81

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11426 Under Construction [under-construction-page] < 5.81 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 5.81 5.81 2026-07-10

CVE-2026-11426

The UnderConstructionPage PRO WordPress plugin contains a security flaw that allows attackers with Subscriber-level access or higher to access sensitive data by exploiting a weakness in how the plugin handles file paths. Specifically, an attacker can specify any local file path when using the template_thumbnail parameter, causing the plugin to copy its contents into a publicly accessible location on the server. This vulnerability affects all versions of the plugin up to and including 5.76.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.