Impact
The vulnerability exists in the Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress. The upload() function accepts a user‑supplied supported_type string and the uploaded filename without enforcing real file extension or MIME checks. Because this validation is missing, an unauthenticated attacker can upload files of any type, which can lead to execution of malicious code or other compromise of the affected site’s server.
Affected Systems
Sites that have installed the Drag and Drop Multiple File Upload for WooCommerce plugin up to and including version 1.1.6. These include any WordPress installation using WooCommerce that relies on this plugin for handling product media uploads.
Risk and Exploitability
With a CVSS score of 9.8, the risk is considered critical. The EPSS score of 3% indicates a non‑negligible chance of exploitation in the current threat landscape. The vulnerability is not listed in CISA’s KEV catalog, but attackers can exploit it remotely via the plugin’s upload endpoint without authentication, making it highly actionable. An attacker could achieve arbitrary code execution on the server by uploading a malicious script or payload.
OpenCVE Enrichment
EUVD