Impact
The CVE concerns an unrestricted upload of files to the aidraw I Draw WordPress plugin. An attacker can upload files deemed dangerous, including executable scripts. If successful, the party may run arbitrary code on the host as the web server's user, compromising confidentiality, integrity, and availability of the site and any underlying infrastructure.
Affected Systems
WordPress sites employing the aidraw I Draw plugin version 1.0 or earlier are affected. This includes any WordPress installation, regardless of underlying operating system or theme, as long as the vulnerable plugin is active.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity. The EPSS score of less than 1% suggests a low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely the web application – an unauthenticated or low‑privilege user can submit a crafted upload request to the vulnerable endpoint. If the server permits execution of the uploaded file, remote code execution ensues.
OpenCVE Enrichment
EUVD