Impact
The vulnerability is an unrestricted file upload flaw that allows an attacker to place a file of any type onto the web server, including a Web Shell. By uploading a malicious script, an attacker can gain the ability to execute arbitrary code on the server, leading to complete compromise of confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
This flaw affects the Web Ready Now WR Price List Manager For WooCommerce plugin for WordPress versions up to and including 1.0.8. WordPress sites that have installed this plugin without updating past 1.0.8 are vulnerable.
Risk and Exploitability
Based on the description, the likely attack vector is remote via the plugin’s upload interface, which may be accessed by authenticated administrators or, depending on configuration, by unauthenticated users. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS score of 9.9 demonstrates a severe risk: an attacker who succeeds can run arbitrary code on the server, effectively taking control of the site and any data it contains.
OpenCVE Enrichment
EUVD