Junglewise Threat Intelligence

CVE-2026-84171: WP Images Upload on Piclect arbitrary file upload

CVE-2026-84171 · Severity: critical · CVSS 9.8 · Published 2026-09-12

Executive brief

WP Images Upload on Piclect is a WordPress plugin that handles image uploads. The plugin fails to validate file names and types before storing uploads in a publicly accessible directory, allowing anyone to upload malicious files and execute code on the website. This gives attackers complete control over the affected WordPress installation and can lead to data theft, website defacement, or use as a platform for spreading malware.

Technical details

The vulnerability is an unauthenticated arbitrary file upload in the WP Images Upload on Piclect WordPress plugin through version 1.0. The plugin does not properly validate either the filename or file type of uploaded files before writing them to a publicly accessible directory, making it susceptible to remote code execution. An unauthenticated attacker can exploit this by uploading a malicious file (such as a PHP shell) which will be accessible and executable on the web server. No authentication is required to trigger the vulnerability, and the attack is network-accessible. As of the advisory date, no patch is known to be available.

Affected products

  • Piclect WP Images Upload on Piclect through 1.0

Timeline

  • 2026-09-10: disclosed: Publicly disclosed on WPScan
  • 2026-09-12: advisory: Published on NVD

References