Impact
The vulnerability arises because the zportals WordPress plugin before version 6.3.4 fails to validate the MIME type of files uploaded by users. It accepts the content type specified by the client and retains the original file extension, which allows any authenticated user with at least Subscriber level to upload and execute arbitrary PHP code. This directly leads to remote code execution on the server, compromising the confidentiality, integrity, and availability of the entire WordPress site.
Affected Systems
The affected product is the zportals WordPress plugin, all releases prior to 6.3.4. Users running any version older than 6.3.4 on a WordPress installation are vulnerable; the vendor identity is unknown but the plugin is hosted in WordPress repositories.
Risk and Exploitability
The CVSS score is not disclosed, but the potential for full remote code execution indicates a high severity. The EPSS score is unavailable, so the probability of exploitation at present is uncertain. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is through legitimate authentication: an attacker who can log in or otherwise obtain a role of Subscriber, Author, Editor, or Administrator can exploit the flaw. Once exploited, the attacker can place malicious PHP files on the server, execute them, and gain non‑privileged access to the web application and potentially the underlying server environment.
OpenCVE Enrichment