WordPress security by component
WP images upload on piclect
WP images upload on piclect (wp-images-upload-on-piclect) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
wp-images-upload-on-piclectLatest vulnerability
CVE-2026-84171: WP images upload on piclect accepts unauthenticated executable uploads
WP images upload on piclect through 1.0 writes unauthenticated uploads to a publicly accessible directory without validating the file name or type. An attacker can upload a PHP file and request it over the web to execute arbitrary code. The authoritative export does not identify the upload handler, multipart field, or destination directory.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-84171
WP images upload on piclect accepts unauthenticated executable uploads
WP images upload on piclect through 1.0 writes unauthenticated uploads to a publicly accessible directory without validating the file name or type. An attacker can upload a PHP file and request it over the web to execute arbitrary code. The authoritative export does not identify the upload handler, multipart field, or destination directory.
|
See mitigation notes |
CVE9.8
NVDPending
|