Executive brief
The Gerador de Certificados – DevApps plugin for WordPress, which is used to generate certificates, contains a security flaw that allows high-level users to upload restricted file types. An attacker with administrative credentials could exploit this to upload malicious scripts to the web server. This could lead to a complete takeover of the website and its underlying server, potentially exposing sensitive data or disrupting operations.
Technical details
The vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434) within the moveUploadedFile() function of the Gerador de Certificados – DevApps plugin. The root cause is a lack of file type validation, allowing any file extension to be processed and stored on the server. While the attack requires Administrator-level privileges, it provides a path for remote code execution (RCE) by uploading PHP scripts. The issue affects all versions up to and including 1.3.6; users should check for updates or patches from the vendor.
Affected products
- tidevapps Gerador de Certificados – DevApps <= 1.3.6
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory