Executive brief
GP Premium is a WordPress plugin used to extend the Genesis theme framework with advanced functionality. An arbitrary file upload vulnerability in versions up to 2.5.5 allows authenticated attackers to upload malicious files to the web server, potentially leading to complete server compromise and remote code execution. This is a critical flaw that attackers are expected to exploit at scale across vulnerable WordPress sites.
Technical details
The vulnerability is an unrestricted file upload flaw (CWE-434) in the GP Premium WordPress plugin. The plugin fails to properly validate or restrict the types of files that can be uploaded, allowing an attacker with contributor or developer privileges to upload executable code or other dangerous file types to the server. By uploading a PHP file or similar script, an attacker can achieve remote code execution and take full control of the affected WordPress installation and underlying server. The vulnerability affects versions 2.5.5 and earlier; version 2.5.6 and later contain the fix.
Affected products
- EDGE22 Studios Ltd. GP Premium <= 2.5.5
Timeline
- 2026-05-27: disclosed: Reported by Austin Ginder
- 2026-08-18: advisory: Published on NVD and Patchstack
- 2026-08-18: patched: Patch available in version 2.5.6