Impact
The Swiss Toolkit For WP plugin contains a flaw in the upload_extension_files() function that validates filenames with a substring check instead of verifying the true file extension. Based on the description, this allows authenticated users with Author-level access or higher to upload arbitrary files, including PHP scripts. If the plugin’s Enhanced Multi‑Format Image Support feature is enabled with non‑image extensions such as avif, the upload bypass can provide a path to execute malicious code on the server.
Affected Systems
WordPress installations running the Swiss Toolkit For WP plugin from Wpmessiah, versions 1.4.6 or earlier, are affected. Any user possessing Author-level or higher privileges on the site can exploit the upload capability to place malicious files on the server.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score of < 1 % points to a very low current exploitation probability, and it is not listed in the CISA KEV catalog. Nonetheless, because many sites grant Authors frequent access and the bypass is relatively easy to exploit, the potential impact remains significant: when the image‑support feature is enabled, arbitrary code can be executed on the web server.
OpenCVE Enrichment