Impact
The flaw allows an attacker to upload any file through the Sync Post With Other Site plugin. By uploading a malicious script or executable, the attacker can gain code execution on the web server. This violates confidentiality, integrity, and availability, as arbitrary code can be run with the privileges of the web server user. The vulnerability is rooted in insufficient file type validation (CWE‑434).
Affected Systems
The vulnerability affects all installations of the Sync Post With Other Site plugin by Kamlesh Parmar that are at or below version 1.9.3. No other vendors or products are impacted beyond this WordPress plugin.
Risk and Exploitability
The CVSS score of 9.9 marks it as Critical, indicating that the flaw can be exploited remotely with minimal user interaction. The EPSS score is not available, but the lack of a KEV listing still means the vulnerability can be widely used if attackers target the plugin. Attackers can typically trigger the upload functionality via an HTTP request, potentially without authentication, and then execute the uploaded file. The high score reflects the significant risk of unauthorized code execution on affected sites.
OpenCVE Enrichment