This vulnerability is highly dangerous and expected to become exploited.
Due to the specific nature of this vulnerability, no virtual patch can be assigned to it.
This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website.
CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.
We advise to mitigate or resolve the vulnerability immediately.
Published by Patchstack
30 Sep, 2025