Sceawere
Vulnerability Detail
CVE-2026-39755UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Duplicate Arbitrary File Upload
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 16h ago
- Vendor
- revmakx
- Product
- WP Duplicate
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-06T09:17:47.237Z",
"pubdate": "2026-10-06T09:17:47.237Z",
"executiveSummary": "The WP Duplicate plugin for WordPress, in all versions up to and including 1.1.11, is susceptible to an arbitrary file upload vulnerability.\nThis flaw allows authenticated users with subscriber-level privileges to upload malicious files to the server.\nThe vulnerability arises from insufficient validation of file types during the upload process within the plugin's functionality.\nSuccessful exploitation permits an attacker to upload executable scripts, such as PHP files, which can then be triggered to achieve remote code execution (RCE) on the underlying server.\nThe impact includes full server compromise, potential data exfiltration, unauthorized access to the database, and further lateral movement within the hosting environment.\nExploitation requires the attacker to have at least a subscriber-level account, though it does not necessitate administrative privileges.\nGiven the severity of potential remote code execution, this vulnerability poses a critical risk to site integrity and security.",
"technicalDetails": "The vulnerability stems from improper input validation within the WP Duplicate plugin, which fails to restrict the types of files that can be uploaded by authenticated users.\nSpecifically, the plugin does not enforce strict allow-lists or perform sufficient content verification on files processed through its upload mechanisms.\nIn the context of the affected versions (<= 1.1.11), the application processes user-supplied file uploads without validating the MIME type or the file extension against known safe formats.\nThe attack flow begins when an attacker, authenticated as a subscriber, accesses the specific functionality provided by WP Duplicate that handles file uploads.\nThe attacker sends a crafted HTTP POST request to the server containing a malicious payload, such as a PHP web shell.\nBecause the plugin lacks adequate server-side checks, it accepts the malicious file and writes it to a location on the web server accessible via the browser.\nOnce the file is successfully uploaded, the attacker can then navigate to the direct URL of the uploaded script, triggering its execution by the web server's PHP interpreter.\nThis execution runs under the privileges of the web server user, allowing the attacker to perform arbitrary commands, read or modify files, and access sensitive information like WordPress configuration files (wp-config.php) containing database credentials.\nThe lack of restrictive file system permissions or an isolated upload directory further facilitates the execution of malicious scripts.\nPost-exploitation activities typically include the deployment of backdoors for persistent access, modification of site content, or the utilization of the server as a node for broader attacks, such as distributing malware or launching internal network scans.\nThe vulnerability is critical due to the ease of exploitation by low-privileged users, who are often able to register accounts on vulnerable installations depending on site configuration."
}