Impact
The Make Connector plugin for WordPress allows authenticated users with Administrator level or higher to upload arbitrary files because the plugin's file type validation in the upload_media function is misconfigured. This flaw can be leveraged to place malicious scripts on the site, potentially giving an attacker the ability to execute code on the web server. The vulnerability is identified as CWE-434, representing unsafe file uploads.
Affected Systems
Any WordPress site running the Integromat Make Connector plugin version 1.5.10 or earlier is affected. Administrators or users with equivalent privileges on those installations can exploit the flaw.
Risk and Exploitability
The CVSS score of 7.2 reflects a moderate to high risk, and the EPSS score of 1% indicates a low but non-zero probability of exploitation. Since the attack requires Administrator or higher credentials, the threat is limited to privileged users, but the ability to upload code gives attackers a powerful vector for remote code execution. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD