Impact
The Everest Toolkit WordPress plugin up to version 1.2.3 fails to validate the file type of uploads performed during the demo‑content import feature. The plugin disables the standard WordPress file‑type check, allowing privileged users to upload arbitrary PHP scripts to the WordPress uploads directory. Once an attacker has uploaded and exfiltrated a PHP file, they can execute it with the same permissions as the web server, enabling full remote code execution on the host. The flaw is a classic example of insecure file upload, tied to CWE‑434, and can compromise confidentiality, integrity, and availability of the site and potentially the underlying server. Affected systems include any WordPress site running Everest Toolkit version 1.2.3 or earlier. The vulnerability is exploitable by administrators, and on a multisite installation, non‑super‑admin site administrators also qualify. The flaw is not limited to a specific network location; any user who can initiate the demo‑content import will have the ability to upload files. Risk and exploitability: The EPSS score indicates a very low likelihood (<1%) of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited in the wild. However, because the attack requires only high‑privilege WordPress authentication, sites with weak administrative policies or exposed backsides could be targeted. The combination of remote code execution potential and privileged access makes this flaw high severity if the plugin is in use.
Affected Systems
Any WordPress site using Everest Toolkit version 1.2.3 or earlier, including multisite setups where site administrators with non‑super‑admin privileges can trigger the demo‑content import.
Risk and Exploitability
The EPSS score indicates a very low likelihood (<1%) of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited in the wild. However, because the attack requires only high‑privilege WordPress authentication, sites with weak administrative policies or exposed backsides could be targeted. The combination of remote code execution potential and privileged access makes this flaw high severity if the plugin is in use.
OpenCVE Enrichment