Description
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
Published: 2026-09-12
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker can upload any file to the public upload directory of the WP Images Upload on Piclect plugin when the version is 1.0 or earlier of the file name attacker can place executable code such as PHP scripts, leading to arbitrary code execution on the web server. The flaw therefore allows an attacker to compromise the confidentiality, integrity, and availability of the affected site by running arbitrary code with the web server’s privileges.

Affected Systems

The vulnerability is present in all releases of the WP Images Upload on Piclect WordPress plugin up to and including version 1.0. The plugin files to a publicly accessible directory. No other products or vendor versions are listed as affected.

Risk and Exploitability

The risk is high because the flaw provides a direct path to execute code without authentication, and the CVSS score of 9.8 indicates a critical severity. EPSS Score: < 1%, and the vulnerability is not listed in CISA KEV, so exploitation frequency is uncertain, but potential impact remains severe. The attack would likely use a simple HTTP POST to the plugin’s upload endpoint, and any unauthenticated user could reach it if the plugin is enabled. A successful exploit would give the attacker the ability to run arbitrary scripts on the server.

Generated by OpenCVE AI on September 15, 2026 at 18:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WP Images Upload on Piclect plugin to the latest version that includes a fix for the unrestricted file upload vulnerability (CWE-434).
  • If an upgrade is not immediately possible, restrict access to the upload directory and enforce a strict whitelist of allowed file types, ensuring server‑side validation (CWE-434).
  • Configure server permissions and disable script execution in the upload directory, setting uploaded files to 0644 and moving the directory outside the web root to mitigate accidental code execution (CWE-434).

Generated by OpenCVE AI on September 15, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
Title WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:31:11.927Z

Reserved: 2026-09-01T08:46:01.259Z

Link: CVE-2026-84171

cve-icon Vulnrichment

Updated: 2026-09-12T15:19:18.764Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:27.137

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-84171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type