Impact
The vulnerability in the quantumcloud WoowBot Pro Max WordPress plugin is a CWE-434 Unrestricted Upload of File With Dangerous Type, allowing an attacker to upload files of any type without restriction, exposing the site to the possibility of malicious payloads being delivered and later executed. By uploading a malicious file, an attacker could potentially introduce code that may run in the context of the web server or the application, compromising data integrity and availability.
Affected Systems
The issue affects the WoowBot Pro Max plugin from quantumcloud for WordPress. Versions from the initial release through 14.1.7 are vulnerable. Any WordPress installation using one of these versions of the plugin is at risk.
Risk and Exploitability
reflecting the very high severity of unrestricted file upload. The CVSS score of 9.9 indicates a critical severity. The EPSS score is less than 1 % indicating that while the likelihood of exploitation at any given time is currently low, the potential impact warrants serious attention. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely via the web interface of the WordPress site: an attacker can exploit the upload functionality through normal web traffic, possibly without needing administrative privileges, depending on how the plugin is configured.
OpenCVE Enrichment