Impact
The tenteeglobal:Instant Appointment plugin for WordPress contains a flaw in the 'insapp_upload_image_as_attachment' function, allowing any file type to be uploaded without validation. An unauthenticated attacker can place executable or malicious files on the web server, creating the possibility of remote code execution. The CVSS score of 9.8 marks this as a critical vulnerability, while the absence of proper file type checks underpins its severity.
Affected Systems
All WordPress installations that have the tenteeglobal:Instant Appointment plugin enabled and are running version 1.2 or earlier are affected. Any site that exposes the plugin’s upload functionality is vulnerable, regardless of user authentication state.
Risk and Exploitability
This flaw is exploitable by sending an upload request to the plugin’s Ajax endpoint. Because the EPSS score is less than 1% the likelihood of real‑world exploitation is currently low, but the CVSS score of 9.8, combined with the lack of in‑place mitigations, means that once an attacker gains the ability to upload, remote code execution could be achieved. The vulnerability is not listed in CISA’s KEV catalog, but its high severity warrants urgent attention.
OpenCVE Enrichment