Impact
The vulnerability allows a subscriber user to upload any file to the server without restriction. This file type validation flaw (CWE‑434) can permit the placement of executable scripts or web shells, enabling the attacker to run code with the privileges of the web server. Successful exploitation could compromise the entire WordPress installation, disclose sensitive data, and provide a foothold for further attacks.
Affected Systems
The flaw is present in the WordPress Business Directory Plugin developed by CMSJunkie, known as WP‑BusinessDirectory. Versions up through 4.0.0 are affected. The plugin is distributed as a WordPress plugin, and any WordPress site installing those versions is vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity, and an EPSS score of less than 1% shows the exploitation probability is currently very low, possibly due to the lack of publicly available exploits or the requirement for authenticated access. The vulnerability is not listed in CISA’s KEV catalog. The attacker would need to authenticate as a subscriber to upload the malicious file, but once uploaded, the file could be accessed as a normal web resource, giving broad access to server resources. The high severity and ability to execute arbitrary code make this a top priority for remediation.
OpenCVE Enrichment