Impact
The DS Ad Rotator WordPress plugin up to version 0.8 contains an unchecked image upload handler that accepts any file type without performing capability checks, nonce verification, or file-type validation. This flaw allows an unauthenticated attacker to upload a malicious file such as a PHP script into a web-accessible directory, which can then be executed by the web server. It represents a CWE-434 weakness and is scored 9.8 on CVSS. The result is remote code execution, giving an attacker full control over the affected site.
Affected Systems
The vulnerability affects installations of the DS Ad Rotator plugin version 0.8 or earlier on WordPress sites. herein, so any instance of the plugin through 0.8 remains vulnerable until the plugin is updated or removed.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%) and the vulnerability is not listed in CISA KEV, but the straightforward attack path: an attacker simply sends a file upload request to the plugin’s handler without authentication. Because the uploaded file can be executed by the web server, the threat level is high despite the low EPSS. The vulnerability is a CWE-434 flaw with a CVSS score of 9.8. The risk remains significant until the plugin is upgraded or the upload functionality is disabled.
OpenCVE Enrichment