๐Ÿ” CVE Alert

CVE-2026-93031

HIGH 8.8

WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box <= 3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload via Media Import

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible.

CWE CWE-434
Vendor wp cloud plugins/_deleeuw_
Product use-your-drive | google drive plugin for wordpress
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for wp cloud plugins/_deleeuw_ use-your-drive | google drive plugin for wordpress

Be the first to know when new high vulnerabilities affecting wp cloud plugins/_deleeuw_ use-your-drive | google drive plugin for wordpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

WP Cloud Plugins/_deleeuw_ / Use-your-Drive | Google Drive plugin for WordPress
2.0 โ‰ค 3.8.3
_DeLeeuw_ / Share-one-Drive | OneDrive & SharePoint plugin for WordPress
2.0 โ‰ค 3.8.3
_DeLeeuw_ / WP Cloud Plugins - Box (Lets-Box)
2.0 โ‰ค 3.8.3
_DeLeeuw_ / WP Cloud Plugins - Dropbox (Out-of-the-Box)
2.0 โ‰ค 3.8.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/a10ab4d6-318e-4dd6-9f81-ed25f181d074?source=cve documentation.wpcloudplugins.com: https://documentation.wpcloudplugins.com/other/changelog#id-3.9.0 wpcloudplugins.gitbook.io: https://wpcloudplugins.gitbook.io/docs/other/changelog

Credits

WP Cloud Plugins