---
id: CVE-2026-11426
title: >-
  The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary
  File Read in all versions up to, and including, 5.76
summary: >-
  The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary
  File Read in all versions up to, and including, 5.76. This is due to the
  plugin accepting arbitrary local file paths in the template_thumbnail
  parameter and co…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11426'
references:
  - url: 'https://underconstructionpage.com/changelog/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/29dff562-e9b0-4cc9-b974-9239fbf0310f?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.0046
epssPercentile: 0.37224
ingestedAt: '2026-07-11T22:16:01.046Z'
---

## Overview

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and copying their contents into a publicly accessible uploads file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server, which can contain sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
