← WordPress Vulnerabilities
WordPress security by component

WP images upload on piclect

WP images upload on piclect (wp-images-upload-on-piclect) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.

Plugin slug: wp-images-upload-on-piclect

CVE-2026-84171: WP images upload on piclect accepts unauthenticated executable uploads

WP images upload on piclect through 1.0 writes unauthenticated uploads to a publicly accessible directory without validating the file name or type. An attacker can upload a PHP file and request it over the web to execute arbitrary code. The authoritative export does not identify the upload handler, multipart field, or destination directory.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wp-images-upload-on-piclect
Safe version
Sep 12, 2026 CVE-2026-84171
WP images upload on piclect accepts unauthenticated executable uploads
WP images upload on piclect through 1.0 writes unauthenticated uploads to a publicly accessible directory without validating the file name or type. An attacker can upload a PHP file and request it over the web to execute arbitrary code. The authoritative export does not identify the upload handler, multipart field, or destination directory.
See mitigation notes
CVE9.8
NVDPending