Impact
The UltimateAI WordPress plugin contains a flaw that lets an attacker upload arbitrary files. The plugin fails to validate file types or extensions, allowing a malicious file to be stored on the server and executed, thereby providing remote code execution. Classified as CWE‑434, this vulnerability can compromise the confidentiality, integrity, and availability of the entire WordPress installation.
Affected Systems
The issue affects all installations of the tophive UltimateAI WordPress plugin version 3.1.0 or earlier. Any WordPress site that has this plugin enabled is vulnerable, regardless of the WordPress core version or other plugins present.
Risk and Exploitability
With a CVSS score of 9.9, the flaw presents high exploitation risk for remote code execution. While the EPSS score is unavailable, the severity rating indicates that attackers could exploit the flaw if an authenticated user has subscriber‑level permissions and can access the plugin’s file upload interface. The vulnerability is not listed in the CISA KEV catalog, but the lack of a formal listing does not diminish the threat, as many sites run the affected plugin and the flaw permits unrestricted code execution if left unpatched.
OpenCVE Enrichment