Impact
An unauthenticated attacker can upload any file to the public upload directory of the WP Images Upload on Piclect plugin when the version is 1.0 or earlier of the file name attacker can place executable code such as PHP scripts, leading to arbitrary code execution on the web server. The flaw therefore allows an attacker to compromise the confidentiality, integrity, and availability of the affected site by running arbitrary code with the web server’s privileges.
Affected Systems
The vulnerability is present in all releases of the WP Images Upload on Piclect WordPress plugin up to and including version 1.0. The plugin files to a publicly accessible directory. No other products or vendor versions are listed as affected.
Risk and Exploitability
The risk is high because the flaw provides a direct path to execute code without authentication, and the CVSS score of 9.8 indicates a critical severity. EPSS Score: < 1%, and the vulnerability is not listed in CISA KEV, so exploitation frequency is uncertain, but potential impact remains severe. The attack would likely use a simple HTTP POST to the plugin’s upload endpoint, and any unauthenticated user could reach it if the plugin is enabled. A successful exploit would give the attacker the ability to run arbitrary scripts on the server.
OpenCVE Enrichment