Impact
The flaw allows an unauthenticated actor to upload any file through the plugin’s file upload interface. Once uploaded, the file can be executed on the host, giving the attacker full control over the compromised environment and leading to loss of confidentiality, integrity, and availability.
Affected Systems
WordPress sites running the wpWax Templatiq plugin version 0.2.5 or earlier are affected. The vulnerability is present in all versions up to and including 0.2.5.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is likely through any exposed upload endpoint, making exploitation straightforward if no further controls are in place.
OpenCVE Enrichment