Impact
WordPress Plugin Peugeot Music 1.0 lets unauthenticated attackers upload files through the /upload.php endpoint. By manipulating the 'name' parameter, attackers can place files with arbitrary extensions in the uploads directory and trigger execution of malicious code, leading to full compromise of the web server.
Affected Systems
The vulnerability affects the Peugeot Music WordPress plugin version 1.0, maintained by peugeot-music-plugin. No other versions or products are listed as impacted.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is considered critical. The EPSS score is presently unavailable, and the vulnerability is not listed in the CISA KEV catalog, but the unauthenticated nature of the attack path suggests that exploitation can occur over the network without prior access. Attackers can simply send crafted POST requests to upload.php, upload a PHP or other executable file, and cause code execution from the webroot.
OpenCVE Enrichment