Impact
The LightSync Pro plugin for WordPress allows authenticated users with Author-level access or higher to upload arbitrary files because the rest_replace_media() function does not validate file types. This flaw corresponds to CWE-434 and could enable an attacker to place malicious scripts on the server, leading to remote code execution.
Affected Systems
LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock for WordPress. All plugin releases up to and including version 2.1.6 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires an authenticated session with at least Author privileges and the ability to use the media upload endpoint exposed by the plugin. Once the attacker uploads a malicious file, remote code execution may be achieved on the host server.
OpenCVE Enrichment