Impact
Mailster versions 4.1.17 and earlier allow an attacker to upload arbitrary files with insufficient type checks associated with CWE-434. This flaw can lead to the placement of malicious scripts or executables on the web server, resulting in remote code execution, defacement, or data exfiltration. The impact spans confidentiality, integrity, and availability by potentially allowing attackers to run code with the permissions of the web server process.
Affected Systems
The vulnerability affects the EverPress Mailster WordPress plugin, versions up to and including 4.1.17. The flaw is addressed in version 4.1.18 and later. Sites that run any Mailster edition <=4.1.17 are susceptible.
Risk and Exploitability
The CVSS base score of 9.1 indicates high severity, while the EPSS score of <1% indicates a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need access to the WordPress admin editor or sufficient permissions (e.g., an Editor role) to use the file upload capability, which then allows uploading PHP or other executable files that the server will interpret. Once such a file is executed, full remote code execution is possible. The lack of a publicly known exploit coupled with the low EPSS further reduces the immediate threat, but the high severity warrants urgent action.
OpenCVE Enrichment