CVE-2026-93031
8.8 HIGHPublished 2026-09-18 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows attackers to upload arbitrary files, leading to potential remote code execution, due to missing capability checks and lack of file validation.
- Exploitability
- Exploitation is moderately hard as it requires authenticated access with subscriber-level permissions and knowledge of the import process.
- Blast radius
- If exploited, the impact could be severe, as it allows remote code execution, potentially compromising the entire WordPress site.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected plugins or upgrade to version 3.8.4 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-6147
- HIGHCVE-2026-12264
- CRITICALCVE-2026-14175
- HIGHCVE-2026-14553
- CRITICALCVE-2026-18143
- HIGHCVE-2026-36467PoC
- HIGHCVE-2026-54416PoC
- CRITICALCVE-2026-70356PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.