Description
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the GP Premium plugin for WordPress allows unauthenticated users to upload files of any type to the server. Because the plugin does not validate file types or enforce any restriction, an attacker could upload a malicious script or executable that then executes within the context of the web application, effectively gaining remote code execution capabilities. This directly compromises the confidentiality, integrity, and availability of the host system and any data processed by the website.

Affected Systems

The vulnerability affects WordPress GP Premium versions 2.5.5 and earlier, developed by EDGE22 Studios Ltd. The fix begins with version 2.5.6; any deployment with 2.5.5 or earlier is susceptible.

Risk and Exploitability

With a CVSS score of 9.9, the flaw is considered critical. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog, but the high score indicates a severe weakness. The most likely attack vector is via the web application's file upload endpoint, where an attacker can use a crafted request to drop a malicious file, causing immediate and catastrophic impact if exploited.

Generated by OpenCVE AI on August 18, 2026 at 15:49 UTC.

Remediation

Vendor Solution

Update the WordPress GP Premium Plugin to the latest available version (at least 2.5.6).


OpenCVE Recommended Actions

  • Upgrade the GP Premium plugin to version 2.5.6 or later.
  • If an upgrade cannot be performed immediately, disable the plugin or block the upload functionality to prevent remote file uploads.
  • Configure the server or WordPress to restrict uploaded files to safe MIME types and enforce strict validation, ensuring that only approved file extensions are accepted.

Generated by OpenCVE AI on August 18, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Edge22 Studios Ltd.
Edge22 Studios Ltd. gp Premium
Wordpress
Wordpress wordpress
Vendors & Products Edge22 Studios Ltd.
Edge22 Studios Ltd. gp Premium
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Title WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Edge22 Studios Ltd. Gp Premium
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T21:25:48.817Z

Reserved: 2026-07-27T14:00:26.966Z

Link: CVE-2026-66627

cve-icon Vulnrichment

Updated: 2026-08-18T15:09:15.636Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:57.563

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-66627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:44Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type