Impact
The vulnerability is an unrestricted upload of dangerous file types that enables an attacker to upload a web shell, permitting arbitrary code execution on the web server and compromising confidentiality, integrity and availability of the WordPress site.
Affected Systems
The affected product is the WordPress plugin Insert or Embed Articulate Content into WordPress developed by Brian Batt at elearningfreak.com. All plugin versions from the initial release through version 4.3000000025 contain the flaw.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical risk, while the EPSS score of < 1% suggests a low probability of exploitation at this time, though the vulnerability is not listed in the CISA KEV catalog. The flaw can be leveraged by any user who can submit a file through the plugin’s upload interface, typically via an unauthenticated or privileged site administrator account, and no additional conditions are required.
OpenCVE Enrichment
EUVD