Impact
The flaw is an unrestricted file upload that allows any file type to be uploaded to a WordPress site, including web shells. Classified as CWE‑434, this weakness can give an attacker the ability to run arbitrary code on the server, compromising data confidentiality, integrity, and the availability of the entire site.
Affected Systems
The Reformer for Elementor plugin from merkulove, in any version up to and including 1.0.5, is affected. WordPress installations using this plugin version are therefore at risk.
Risk and Exploitability
With a CVSS score of 10, the vulnerability is deemed critical, yet the EPSS score of less than 1% indicates that exploitation in the wild is currently very unlikely. It is not listed in CISA's KEV catalog. Nonetheless, if an attacker can reach the plugin’s upload interface—likely requiring authenticated access—he or she could upload a web shell and achieve full remote code execution, thereby taking control of the site.
OpenCVE Enrichment
EUVD