Impact
The plugin allows arbitrary of executable file extensions to the global WordPress MIME allowlist. An authenticated user with author-level access can upload files such as .exe, .apk, or .msi, which are then stored site-wide and can be executed, resulting in remote upload being registered on every request without limiting its scope to digital product uploads.
Affected Systems
'Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress' for WordPress sites, affecting all versions up to and including 4.16.18.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, but the EPSS score is less than 1%, suggesting that exploitation is currently unlikely. The vulnerability is not listed in CISA's KEV catalog. Attackers require only author-level credentials and can exploit the flaw via the plugin's file upload interface; because the filter is globally applied, the risk extends across all upload contexts on the site. Until a fix is deployed, the exposure remains for any authenticated author or higher.
OpenCVE Enrichment