Impact
The vulnerability resides in the import functionality of the WP Cloud Plugins set, allowing a subscriber‑level authenticated attacker to upload arbitrary files. The flaw stems from an unauthenticated AJAX endpoint, a missing capability check, and no validation of the file type or contents before writing to the uploads folder. The attacker can upload executable or script files, directly enabling remote code execution.
Affected Systems
Entities affected include WordPress sites running any of the WP Cloud Plugins developed by De Leeuw: Use‑your‑Drive, Share‑one‑Drive, Lets‑Box, and Out‑of‑the‑Box. Versions from the initial release 2.0 through 3.8.3 are susceptible; update to 3.9.0 or later to mitigate.
Risk and Exploitability
The CVSS score of 8.8 highlights a high severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time, though the vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires authenticated access at subscriber level or higher; the attacker may leverage the plugin’s media import to place malicious files in the uploads directory, which can then be executed if PHP execution is enabled or the file is served as a web-accessible script. Given the remote code execution potential, the risk warrants prompt action.
OpenCVE Enrichment