Impact
The DS Ad Rotator WordPress plugin up to version 0.8 contains an unchecked image upload handler that accepts any file type without performing capability checks, nonce verification, or file‑type validation. This flaw allows an unauthenticated attacker to upload a malicious file such as a PHP script into a web‑accessible directory, which can then be executed by the web server. The result is remote code execution, giving an attacker full control over the affected site.
Affected Systems
The vulnerability affects installations of the DS Ad Rotator plugin version 0.8 or earlier on WordPress sites. No patch or fixed version is listed herein, so any instance of the plugin through 0.8 remains vulnerable until the plugin is updated or removed.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%) and the vulnerability is not listed in CISA KEV, but the lack of input validation and access control creates a straightforward attack path: an attacker simply sends a file upload request to the plugin’s handler without authentication. Because the uploaded file can be executed by the web server, the threat level is high despite the low EPSS. The risk remains significant until the plugin is upgraded or the upload functionality is disabled.
OpenCVE Enrichment