Impact
The BeeTeam368 Extensions plugin for WordPress contains an unchecked file‑type validation flaw in its handle_submit_upload_file() routine. Because any authenticated user with Subscriber or higher privileges can upload any file that passes the size tests, the flaw enables an attacker to place a malicious script on the site’s server, creating a path to remote code execution. This is an unrestricted file upload weakness (CWE-434) rated with a CVSS v3.1 score of 8.8, indicating high severity.
Affected Systems
The vulnerability affects the BeeTeam368 Extensions plugin for WordPress up to and including version 2.3.5. All site owners running any of these versions are potentially exposed until an updated release is applied.
Risk and Exploitability
The CVSS score of 8.8 signals a high impact if the flaw is abused, but the EPSS of <1% suggests low current exploitation activity. The flaw requires an authenticated session, so it is not remote from the outset. However, any subscriber or user with elevated privileges can trigger exploitation, making it a significant risk for sites with broad Subscriber permissions. Without a patch, an attacker may launch a hostile file upload that could lead to arbitrary code execution.
OpenCVE Enrichment
EUVD