Impact
The Kalrav AI Agent plugin for WordPress is vulnerable because the kalrav_upload_file AJAX action lacks file type validation, allowing an attacker to upload arbitrary files. This flaw can lead to remote code execution on the site. The weakness corresponds to CWE-434, Missing File Type Validation.
Affected Systems
The issue impacts the Kalrav AI Agent plugin from irisideatechsolutions for WordPress, with all releases up to and including version 2.3.3 vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity, and an EPSS score of less than 1%, suggesting a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. The attack vector is unauthenticated via a public AJAX endpoint, meaning any visitor can perform the exploit.
OpenCVE Enrichment