🔐 CVE Alert

CVE-2026-84171

CRITICAL 9.8

WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

Vendor unknown
Product wp images upload on piclect
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp images upload on piclect

Be the first to know when new critical vulnerabilities affecting unknown wp images upload on piclect are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / WP images upload on piclect
0 ≤ 1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/e5b9fd87-92a7-4fc6-b8b2-896b87d97c40/

Credits

João Ramos Maciel WPScan