« Volver al listado

CVE-2026-93031

Estado: AplazadaAlta (8.8)—

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-434 (arbitrary file upload) en función AJAX sin validación de extensión/contenido en plugins WordPress. Autenticación de suscriptor + escalada: ejecución remota de código mediante web shell.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93031",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-93031",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-19T13:20:08.066792Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@wordfence.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@wordfence.com",
      "affectedData": [
        {
          "vendor": "WP Cloud Plugins/_deleeuw_",
          "product": "Use-your-Drive | Google Drive plugin for WordPress",
          "versions": [
            {
              "status": "affected",
              "version": "2.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.8.3"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "_DeLeeuw_",
          "product": "Share-one-Drive | OneDrive & SharePoint plugin for WordPress",
          "versions": [
            {
              "status": "affected",
              "version": "2.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.8.3"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "_DeLeeuw_",
          "product": "WP Cloud Plugins - Box (Lets-Box)",
          "versions": [
            {
              "status": "affected",
              "version": "2.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.8.3"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "_DeLeeuw_",
          "product": "WP Cloud Plugins - Dropbox (Out-of-the-Box)",
          "versions": [
            {
              "status": "affected",
              "version": "2.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.8.3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-18T20:17:31.630",
  "references": [
    {
      "url": "https://documentation.wpcloudplugins.com/other/changelog#id-3.9.0",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://wpcloudplugins.gitbook.io/docs/other/changelog",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a10ab4d6-318e-4dd6-9f81-ed25f181d074?source=cve",
      "source": "security@wordfence.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@wordfence.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible."
    }
  ],
  "lastModified": "2026-09-21T13:33:33.387",
  "sourceIdentifier": "security@wordfence.com"
}