Impact
The vulnerability resides in the Product Input Fields for WooCommerce WordPress plugin before version 2.0.2, where the plugin does not restrict file types when the accepted‑types setting is left blank. This omission allows an attacker to upload any file without authentication and, on servers that do not enforce directory access controls, execute that code, resulting in full remote code execution.
Affected Systems
Any WordPress site using the Product Input Fields for WooCommerce plugin version earlier than 2.0.2 is potentially affected, regardless of the site owner or host, as the issue is in the plugin itself and not dependent on other components.
Risk and Exploitability
The EPSS score is below 1%, showing a low probability of exploitation, yet the CVSS score of 9.8 demonstrates a critical impact. KEV has not listed this vulnerability, but the high severity indicates it requires prompt attention. The attacker can upload any file without authentication and, on servers that allow execution of uploads, run arbitrary code, leading to full remote control of the affected system.
OpenCVE Enrichment