Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deleeuw
Deleeuw share-one-drive | Onedrive & Sharepoint Plugin For Wordpress Deleeuw wp Cloud Plugins - Box (lets-box) Deleeuw wp Cloud Plugins - Dropbox (out-of-the-box) Wordpress Wordpress wordpress Wp Cloud Plugins/ Deleeuw Wp Cloud Plugins/ Deleeuw use-your-drive | Google Drive Plugin For Wordpress |
|
| Vendors & Products |
Deleeuw
Deleeuw share-one-drive | Onedrive & Sharepoint Plugin For Wordpress Deleeuw wp Cloud Plugins - Box (lets-box) Deleeuw wp Cloud Plugins - Dropbox (out-of-the-box) Wordpress Wordpress wordpress Wp Cloud Plugins/ Deleeuw Wp Cloud Plugins/ Deleeuw use-your-drive | Google Drive Plugin For Wordpress |
Sat, 19 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. | |
| Title | WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box <= 3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload via Media Import | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-19T14:11:38.229Z
Reserved: 2026-09-17T15:11:46.407Z
Link: CVE-2026-93031
Updated: 2026-09-19T14:04:38.088Z
Status : Received
Published: 2026-09-18T20:17:31.630
Modified: 2026-09-19T15:17:08.210
Link: CVE-2026-93031
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:28:28Z