CVE-2026-84171
Received Received - Intake

Unauthenticated File Upload in Piclect WordPress Plugin

Vulnerability report for CVE-2026-84171, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
piclect wp_images_upload to 1.0 (exc)
piclect wp_images_upload 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the WP Images Upload plugin for WordPress (version 1.0 or below). It allows unauthenticated attackers to upload arbitrary files to a publicly accessible directory without validation of file names or types. This can lead to arbitrary code execution on the server.

Detection Guidance

Check if the WP Images Upload on Piclect plugin version 1.0 or below is installed. Look for unexpected files in publicly accessible directories like /wp-content/uploads/. Monitor network traffic for unauthorized file uploads or suspicious POST requests to plugin endpoints.

Impact Analysis

Attackers could exploit this to upload malicious files, such as web shells, which could give them control over your server. This may result in data theft, defacement, or further compromise of your WordPress site or hosting environment.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and security. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Disable or uninstall the WP Images Upload on Piclect plugin immediately. Restrict write permissions on upload directories. Implement file upload validation at the server level. Monitor for signs of exploitation and consider blocking uploads until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84171. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart