GHSA-qgr2-56q2-3f39CriticalCVSS 9.8

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type...

Published
September 12, 2026
Last Modified
September 12, 2026

🔗 CVE IDs covered (1)

📋 Description

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

🔗 References (3)