Impact
An unrestricted upload feature in SoftClever Limited’s Sync Posts plugin permits attackers to upload files of any type. This flaw is identified as CWE-434 and can be abused to place a web shell on the WordPress server, giving an attacker the ability to execute arbitrary commands, access sensitive data, or pivot to other systems. The CVSS score of 9.9 reflects a high severity, confirming the potential for complete compromise of the affected system.
Affected Systems
All installations of the Sync Posts plugin version 1.0 and earlier – any WordPress site that has not updated beyond version 1.0 is vulnerable. No specific sub‑versions are listed, so the entire range up to and including 1.0 is considered affected.
Risk and Exploitability
The EPSS score of <1% suggests that exploitation of this vulnerability is currently rare, yet the attack vector is clear: an authenticated or guest user can exploit the file upload endpoint to drop a malicious script. Because the flaw allows uploading of arbitrary file types, a web shell or other malicious payload can be directly placed in the web root, leading to remote code execution. The vulnerability is not listed in CISA’s KEV catalog, but the combination of a high CVSS score and the ability to execute code warrants immediate action.
OpenCVE Enrichment
EUVD