GHSA-qgr2-56q2-3f39CriticalCVSS 9.8
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type...
🔗 CVE IDs covered (1)
📋 Description
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.