Impact
A flaw in the GP Premium plugin for WordPress permits unauthenticated users to upload files of any type without validation, enabling the execution of malicious code on the web server. The attacker can upload a dangerous script or executable, which the plugin then stores on the server and may execute when accessed, resulting in remote code inclusion. This vulnerability compromises confidentiality, integrity and availability by allowing attackers full control of the site.
Affected Systems
The vulnerability affects WordPress GP Premium versions 2.5.5 and earlier, developed by EDGE22 Studios Ltd. The fix begins with version 2.5.6; any deployment with 2.5.5 or earlier is susceptible.
Risk and Exploitability
With a CVSS score of 9.9, the flaw is considered critical. The EPSS score of 0.00447 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is via the web application's file upload endpoint, where an attacker can use a crafted request to drop a malicious file, causing immediate and catastrophic impact if exploited.
OpenCVE Enrichment