Description
Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1.
Published: 2025-11-06
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Advanced Settings plugin implements an upload mechanism that accepts files without validating the MIME type, permitting an attacker to place a malicious script such as a web shell on the server. Once uploaded, the attacker can execute arbitrary PHP code, effectively gaining remote code execution and full control over the affected WordPress instance.

Affected Systems

The flaw exists in the Helmut Wandl Advanced Settings WordPress plugin, affecting all releases from the initial version up through 3.1.1. The vulnerability is present in all installations of these versions unless the plugin is otherwise disabled or the upload feature is removed.

Risk and Exploitability

The CVSS score of 9.1 signals a severe risk. The EPSS score indicates that, although the probability of exploitation is currently low, the presence of a web shell upload remains a critical concern for operators unaware of the issue. The vulnerability is not yet listed in CISA KEV. Attackers can exploit this flaw by using the plugin’s upload interface, which most likely requires an authenticated administrator or privileged user. Because the plugin allows storing PHP files, once the file is uploaded, an attacker may directly access the script through the web server to execute arbitrary code.

Generated by OpenCVE AI on April 29, 2026 at 13:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Advanced Settings plugin to the latest version that removes the vulnerability (consult vendor release notes for version 3.2 or later).
  • If an immediate upgrade is not possible, disable the upload feature within the plugin by editing its settings or removing the upload form from the plugin configuration files.
  • Enforce strict file type restrictions at the WordPress level by setting upload_ext or using security plugins to block executable file uploads.

Generated by OpenCVE AI on April 29, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 17 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 06 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1.
Title WordPress Advanced Settings Plugin <= 3.1.1 - Arbitrary File Upload Vulnerability
Weaknesses CWE-434
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:17:10.233Z

Reserved: 2025-09-06T04:45:29.150Z

Link: CVE-2025-58996

cve-icon Vulnrichment

Updated: 2025-11-17T15:50:56.330Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:01.140

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-58996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:00:12Z

Weaknesses