Description
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
Published: 2025-04-10
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to upload a web shell or other malicious code to a WordPress site because the plugin does not validate the type of files being uploaded. Uploading an arbitrary script gives the attacker full code‑execution capabilities on the web server, enabling theft of data, defacement, or further exploitation. The weakness is a classic unrestricted file‑upload flaw and is identified as CWE‑434, which undermines confidentiality, integrity, and availability of the affected system.

Affected Systems

The WP Remote Thumbnail plugin by Nirmal Kumar Ram for WordPress is affected through version 1.3.2. Any installation of the plugin that is version 1.3.2 or earlier is potentially vulnerable and should be scanned for presence on WordPress sites.

Risk and Exploitability

The CVSS score of 9.9 categorizes this vulnerability as critical, while the EPSS score of less than 1% indicates that it is not currently a common exploitation target but could be sought by attackers who discover it. The likely attack vector is via the plugin’s upload endpoint, reachable through the WordPress admin interface or a public API that the plugin exposes, as inferred from the description. Successful exploitation results in arbitrary code execution on the web server, allowing an adversary to compromise the whole site beyond the plugin scope. Existing web application firewalls alone are insufficient to mitigate this flaw.

Generated by OpenCVE AI on May 1, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Remote Thumbnail to a version newer than 1.3.2 or remove the plugin if upgrading is not possible.
  • Disable the plugin’s upload capability by modifying its configuration or by removing any upload handler code until a patch is applied.
  • Update file system permissions on the upload directory to prevent execution of uploaded files, ensuring that only the web server can read the files and that they are not executable.

Generated by OpenCVE AI on May 1, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10481 Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail allows Upload a Web Shell to a Web Server. This issue affects WP Remote Thumbnail: from n/a through 1.3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail allows Upload a Web Shell to a Web Server. This issue affects WP Remote Thumbnail: from n/a through 1.3.1. Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
Title WordPress WP Remote Thumbnail Plugin <= 1.3.1 - Arbitrary File Upload vulnerability WordPress WP Remote Thumbnail Plugin <= 1.3.2 - Arbitrary File Upload vulnerability
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 10 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail allows Upload a Web Shell to a Web Server. This issue affects WP Remote Thumbnail: from n/a through 1.3.1.
Title WordPress WP Remote Thumbnail Plugin <= 1.3.1 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:17.002Z

Reserved: 2025-04-04T10:00:42.738Z

Link: CVE-2025-32140

cve-icon Vulnrichment

Updated: 2025-04-10T14:01:10.499Z

cve-icon NVD

Status : Deferred

Published: 2025-04-10T08:15:16.373

Modified: 2026-04-23T15:28:37.893

Link: CVE-2025-32140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:45:05Z

Weaknesses