Impact
The Gpx2Graphics WordPress plugin version 0.3 does not perform a CSRF check when handling file uploads and does not validate the uploaded file type. A logged‑in administrator can be tricked into submitting an arbitrary file, such as a PHP script, enabling the attacker to execute code on the server. This flaw is identified as a CWE‑352 Cross‑Site Request Forgery and a CWE‑434 Arbitrary File Upload, and it permits the attacker to run malicious code on the affected site.
Affected Systems
Any WordPress installation that includes the Gpx2Graphics plugin at version 0.3 or earlier is vulnerable. Administrators who leave an active session while the plugin remains enabled are the primary target for exploitation.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level, while the EPSS score of <1% suggests that exploitation is currently rare but still possible. The attack requires a CSRF request that a logged‑in administrator could unknowingly submit, and because the plugin accepts any file type, the attacker can upload and execute a PHP file. The vulnerability is not listed in the CISA KEV catalog, indicating no currently observed large‑scale exploitation, but the risk is theoretically high due to the nature of the flaw.
OpenCVE Enrichment