Impact
The vulnerability is an arbitrary file upload flaw that allows an attacker to upload any file type, including executable web shells. This flaw is identified as CWE-434. An attacker could upload a malicious script and then execute it on the web server, leading to full remote code execution and compromising the entire site and any servers it interacts with.
Affected Systems
Affected systems are WordPress sites using the LiquidThemes AI Hub plugin version 1.3.7 or earlier. This includes all installations from the first available version up through 1.3.7.
Risk and Exploitability
The CVSS score of 10 indicates critical severity, but the EPSS score is less than 1%, suggesting a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Likely the attack involves interacting with the plugin’s upload endpoint remotely, and assuming the site allows unauthenticated users or an attacker has sufficient permissions to upload files.
OpenCVE Enrichment
EUVD