← Back to search

CVE-2026-93031

8.8 HIGH

Published 2026-09-18 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows attackers to upload arbitrary files, leading to potential remote code execution, due to missing capability checks and lack of file validation.
Exploitability
Exploitation is moderately hard as it requires authenticated access with subscriber-level permissions and knowledge of the import process.
Blast radius
If exploited, the impact could be severe, as it allows remote code execution, potentially compromising the entire WordPress site.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected plugins or upgrade to version 3.8.4 or later.
rcewebuploadauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.