Impact
The WordPress File Upload plugin, versions 5.1.10 and earlier, contains an unauthenticated SQL Injection flaw (CWE‑89). An attacker can inject arbitrary SQL statements through the plugin’s upload functionality, potentially reading, modifying, or deleting database contents. This can lead to a full compromise of the website’s data, including user credentials and sensitive configuration information, and may also allow a malicious user to elevate privileges or alter site behavior.
Affected Systems
Anyone hosting a WordPress site that has the WordPress File Upload plugin installed and has a version ≤ 5.1.10 is at risk. The plugin is developed by nickboss and distributed through the WordPress plugin repository. The vulnerability affects all installations that rely on the default upload handling of the plugin without additional safeguards.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The plugin exposes the flaw to unauthenticated users, lowering the required skill level and barrier to exploitation. Although EPSS data is not available and the issue is not currently listed in the CISA KEV catalog, the public availability of this flaw makes the risk high. Site owners should immediately update the plugin or otherwise restrict the upload capability to mitigate the vulnerability.
OpenCVE Enrichment