Impact
The vulnerability allows an attacker to upload files without any type checks, permitting the placement of malicious code that can be executed on the server. This flaw can compromise confidentiality, integrity, and availability by enabling remote code execution or other destructive actions.
Affected Systems
The ReachShip WooCommerce Multi-Carrier & Conditional Shipping plugin by ELEXtensions, versions up to and including 4.3.1, is affected. No earlier versions are impacted.
Risk and Exploitability
The CVSS score of 9.9 signals critical severity, while the EPSS score of <1% indicates a low likelihood of seen exploitation. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is through the plugin’s file upload interface, which requires access to the WordPress administration area. An authenticated attacker could upload a malicious file, such as a web shell, and subsequently trigger its execution, thereby gaining full control of the affected site.
OpenCVE Enrichment
EUVD