CVE-2026-84171
WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
| Vendor | unknown |
| Product | wp images upload on piclect |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp images upload on piclect
Be the first to know when new critical vulnerabilities affecting unknown wp images upload on piclect are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / WP images upload on piclect
0 ≤ 1.0
References
Credits
João Ramos Maciel WPScan