Description
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
Published: 2026-07-13
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the quantumcloud WoowBot Pro Max WordPress plugin is a CWE-434 Unrestricted Upload of File With Dangerous Type, allowing an attacker to upload files of any type without restriction, exposing the site to the possibility of malicious payloads being delivered and later executed. By uploading a malicious file, an attacker could potentially introduce code that may run in the context of the web server or the application, compromising data integrity and availability.

Affected Systems

The issue affects the WoowBot Pro Max plugin from quantumcloud for WordPress. Versions from the initial release through 14.1.7 are vulnerable. Any WordPress installation using one of these versions of the plugin is at risk.

Risk and Exploitability

reflecting the very high severity of unrestricted file upload. The CVSS score of 9.9 indicates a critical severity. The EPSS score is less than 1 % indicating that while the likelihood of exploitation at any given time is currently low, the potential impact warrants serious attention. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely via the web interface of the WordPress site: an attacker can exploit the upload functionality through normal web traffic, possibly without needing administrative privileges, depending on how the plugin is configured.

Generated by OpenCVE AI on July 31, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of the WoowBot Pro Max plugin (greater than 14.1.7).
  • Disable or remove the file upload feature provided by required.
  • Restrict the upload functionality to admin users only and enable server-side file type validation or whitelist checks.

Generated by OpenCVE AI on July 31, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud woowbot Pro Max
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud woowbot Pro Max
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
Title WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Quantumcloud Woowbot Pro Max
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:51.047Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57710

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:10.050Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type