Impact
The vulnerability is an unrestricted upload of files with dangerous MIME types in the WordPress Crossword Compiler Puzzles plugin, enabling an attacker to upload a web shell and achieve remote code execution on the server. This flaw falls under CWE-434 and directly compromises the confidentiality, integrity, and availability of the affected system.
Affected Systems
The affected product is Wordwebsoftware’s Crossword Compiler Puzzles plugin for WordPress, versions from the initial release through 5.2 inclusive. Any deployment of these versions is vulnerable and requires remediation.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, while the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would exploit the plugin’s public upload interface, which is inferred from the description, to place malicious files in a web‑accessible directory where they can be executed.
OpenCVE Enrichment
EUVD