Impact
The plugin contains an unchecked file upload mechanism that permits an attacker to upload any file type. If the file is a script, it may be executed on the server, allowing the attacker to run arbitrary code or retrieve sensitive information. The vulnerability directly enables a compromise of the website’s confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the CodeBard Help Desk WordPress plugin in all releases up to and including version 1.1.2. Any WordPress site that has installed this plugin and has not applied a newer version is potentially exposed.
Risk and Exploitability
A CVSS score of 9.9 classifies the issue as Critical, indicating a high potential impact. Although the EPSS score is unavailable, the absence of an exploit in the KEV database does not diminish the seriousness; the local or remote attacker can leverage the web interface to upload a malicious file. The attack vector is inferred to be network-based, with minimal prerequisites beyond access to the subscriber upload form.
OpenCVE Enrichment