Description
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Published: 2026-07-23
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mailster versions 4.1.17 and earlier allow an attacker to upload arbitrary files with insufficient type checks associated with CWE-434. This flaw can lead to the placement of malicious scripts or executables on the web server, resulting in remote code execution, defacement, or data exfiltration. The impact spans confidentiality, integrity, and availability by potentially allowing attackers to run code with the permissions of the web server process.

Affected Systems

The vulnerability affects the EverPress Mailster WordPress plugin, versions up to and including 4.1.17. The flaw is addressed in version 4.1.18 and later. Sites that run any Mailster edition <=4.1.17 are susceptible.

Risk and Exploitability

The CVSS base score of 9.1 indicates high severity, while the EPSS score of <1% indicates a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need access to the WordPress admin editor or sufficient permissions (e.g., an Editor role) to use the file upload capability, which then allows uploading PHP or other executable files that the server will interpret. Once such a file is executed, full remote code execution is possible. The lack of a publicly known exploit coupled with the low EPSS further reduces the immediate threat, but the high severity warrants urgent action.

Generated by OpenCVE AI on August 3, 2026 at 22:37 UTC.

Remediation

Vendor Solution

Update the WordPress Mailster Plugin to the latest available version (at least 4.1.18).


OpenCVE Recommended Actions

  • Apply the latest Mailster update (4.1.18 or newer).
  • If an update cannot be performed immediately, disable the editor’s file upload feature or remove the plugin entirely to prevent unauthorized uploads.
  • Delete any suspicious or untrusted files from the site’s upload directories.
  • Monitor server logs for unexpected file upload activity and any execution of uploaded files.

Generated by OpenCVE AI on August 3, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Everpress
Everpress mailster
Wordpress
Wordpress wordpress
Vendors & Products Everpress
Everpress mailster
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Title WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Everpress Mailster
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:02:08.355Z

Reserved: 2026-02-17T13:23:42.767Z

Link: CVE-2026-27064

cve-icon Vulnrichment

Updated: 2026-07-23T15:02:00.473Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:16.810

Modified: 2026-07-23T16:17:16.853

Link: CVE-2026-27064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type