Description
Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion.

This issue affects GP Premium: from n/a through 2.5.5.
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Upload leading to Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the GP Premium plugin for WordPress permits unauthenticated users to upload files of any type without validation, enabling the execution of malicious code on the web server. The attacker can upload a dangerous script or executable, which the plugin then stores on the server and may execute when accessed, resulting in remote code inclusion. This vulnerability compromises confidentiality, integrity and availability by allowing attackers full control of the site.

Affected Systems

The vulnerability affects WordPress GP Premium versions 2.5.5 and earlier, developed by EDGE22 Studios Ltd. The fix begins with version 2.5.6; any deployment with 2.5.5 or earlier is susceptible.

Risk and Exploitability

With a CVSS score of 9.9, the flaw is considered critical. The EPSS score of 0.00447 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is via the web application's file upload endpoint, where an attacker can use a crafted request to drop a malicious file, causing immediate and catastrophic impact if exploited.

Generated by OpenCVE AI on September 8, 2026 at 02:12 UTC.

Remediation

Vendor Solution

Update the WordPress GP Premium Plugin to the latest available version (at least 2.5.6).


OpenCVE Recommended Actions

  • Upgrade the GP Premium plugin to version 2.5.6 or later.
  • If an upgrade cannot be performed immediately, disable the plugin or block the upload functionality to prevent remote file uploads.
  • Configure the server or WordPress to restrict uploaded files to safe MIME types and enforce strict validation, ensuring that only approved file extensions are accepted.

Generated by OpenCVE AI on September 8, 2026 at 02:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Edge22 Studios Ltd.
Edge22 Studios Ltd. gp Premium
Wordpress
Wordpress wordpress
Vendors & Products Edge22 Studios Ltd.
Edge22 Studios Ltd. gp Premium
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Title WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Edge22 Studios Ltd. Gp Premium
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-07T23:48:11.365Z

Reserved: 2026-07-27T14:00:26.966Z

Link: CVE-2026-66627

cve-icon Vulnrichment

Updated: 2026-08-18T15:09:15.636Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:57.563

Modified: 2026-09-08T00:16:52.683

Link: CVE-2026-66627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T02:15:08Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type