WP images upload on piclect vulnerability

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

Published 12 Sep 2026Updated 12 Sep 20261 sources
CVSS 0.0

Source timeline

CVE record published by NVDView source ↗