Executive brief
The Ultimate Product Catalog plugin for WordPress, which is used to manage and display product listings, contains a security flaw in its file upload system. An authorized user with basic permissions (such as a contributor or author) can upload malicious files, including web shells, to the server. This could allow an attacker to take complete control of the website, access sensitive data, or disrupt business operations.
Technical details
An arbitrary file upload vulnerability exists in the WordPress Ultimate Product Catalog plugin (v3.8.6 and below) due to insufficient file extension validation in the UPCP_Handle_File_Upload function within Update_Admin-Databases.php. The flaw is exploitable by authenticated users with roles ranging from Contributor to Administrator. By creating a custom field of type 'file' and attaching a malicious PHP script to a product, an attacker can upload a web shell to the /wp-content/uploads/upcp-product-file-uploads/ directory. Since the plugin does not restrict file types or sanitize extensions, the uploaded script can be executed remotely, leading to full Remote Code Execution (RCE). The vulnerability specifically affects the premium version of the plugin where custom fields are enabled.
Affected products
- Etoile Web Design Ultimate Product Catalog <= 3.8.6
Timeline
- 2015-08-08: other: Vulnerability discovered
- 2016-06-21: disclosed: Reported to vendor (no response)
- 2016-06-24: advisory: Public disclosure via Exploit-DB
- 2026-06-15: advisory: NVD/VulnCheck advisory published