Impact
The vulnerability is an arbitrary file upload flaw that allows an attacker to upload a file with a potentially dangerous type. Coupled with path traversal, an attacker could place files outside the intended upload directory. This flaw can enable the deployment of malicious code that the server may execute, leading to full compromise of the affected WordPress site.
Affected Systems
Affected software is the Cozmoslabs WP Webhooks plugin for WordPress. Any installation of WP Webhooks version 3.3.8 or earlier is vulnerable. The plugin is compatible with WordPress installations that use it.
Risk and Exploitability
The CVSS score is 9, indicating a high severity. The EPSS score of less than 1% suggests exploitation is not currently widespread, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw is remote and can be triggered by submitting a crafted HTTP request to the plugin’s upload endpoint. The likely attack vector is through direct upload via the plugin, possibly requiring a logged‑in user with upload rights; however the description does not state authentication requirements, so it is inferred that an attacker could reach the upload point directly. If exploited, the attacker could execute arbitrary code on the server.
OpenCVE Enrichment