CyberRota Analysis
AI-GeneratedThe Insert or Embed Articulate Content plugin for WordPress versions up to 4.3000000027 is vulnerable due to inadequate validation of uploaded archive contents, allowing Editor-level users to upload server-executable files into public directories. This flaw can lead to remote code execution on affected servers, posing a significant risk to site integrity and security. WordPress site administrators, especially those with Editor-level access, should prioritize addressing this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.