Impact
The Solace Extra plugin for WordPress contains an unrestricted file upload flaw that allows an attacker to upload a malicious payload such as a PHP web shell. The vulnerability is a classic input validation weakness defined by CWE-434, and the ability to execute an arbitrary file could give the attacker full control over the web host, potentially leading to data loss, site defacement, or further lateral movement.
Affected Systems
Any WordPress site running Solace Extra versions n/a through 1.3.1 is affected. The flaw applies to all installations of the plugin that have not upgraded beyond version 1.3.1.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is low at present; however, the vulnerability is not listed in CISA KEV. An attacker could exploit the flaw by submitting a crafted upload request through the plugin’s web interface, which may be publicly accessible. Without mitigation, the risk is that an attacker can execute code on the server and compromise the entire WordPress site.
OpenCVE Enrichment
EUVD