Impact
The WordPress iSpring Embedder plugin is vulnerable to a CSRF flaw that allows an attacker to upload arbitrary files, including malicious web shells, giving the attacker remote code execution on the web server. The weakness is classified as CWE‑352.
Affected Systems
The affected product is Harsh iSpring Embedder for WordPress, versions up to and including 1.0. Any site running this plugin version is impacted.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity, and the EPSS of 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by sending a forged request that a logged‑in user executes, enabling them to upload malicious code and achieve full server compromise.
OpenCVE Enrichment
EUVD