CVE-2026-2216

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
09/02/2026
Last modified:
09/02/2026

Description

A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file apis/tools.py. Executing a manipulation of the argument filename can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used.