Impact
A flaw in the GP Premium plugin for WordPress allows unauthenticated users to upload files of any type to the server. Because the plugin does not validate file types or enforce any restriction, an attacker could upload a malicious script or executable that then executes within the context of the web application, effectively gaining remote code execution capabilities. This directly compromises the confidentiality, integrity, and availability of the host system and any data processed by the website.
Affected Systems
The vulnerability affects WordPress GP Premium versions 2.5.5 and earlier, developed by EDGE22 Studios Ltd. The fix begins with version 2.5.6; any deployment with 2.5.5 or earlier is susceptible.
Risk and Exploitability
With a CVSS score of 9.9, the flaw is considered critical. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog, but the high score indicates a severe weakness. The most likely attack vector is via the web application's file upload endpoint, where an attacker can use a crafted request to drop a malicious file, causing immediate and catastrophic impact if exploited.
OpenCVE Enrichment