{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/share-one-drive-2.0---3.8.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-93031"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Use-your-Drive (2.0 - 3.8.3)","Out-of-the-Box (2.0 - 3.8.3)","Share-one-Drive (2.0 - 3.8.3)","Lets-Box (2.0 - 3.8.3)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","cve-2026-93031","rce"],"_cs_type":"advisory","_cs_vendors":["WP Cloud Plugins"],"content_html":"\u003cp\u003eThe WP Cloud Plugins suite - including Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box - contains an arbitrary file upload vulnerability affecting versions 2.0 through 3.8.3. The flaw resides within the \u003ccode\u003edownload_file_to_uploads\u003c/code\u003e function. Due to the improper registration of the import action via \u003ccode\u003ewp_ajax_nopriv_\u003c/code\u003e and a missing capability check in the \u003ccode\u003ecan_import()\u003c/code\u003e function, the plugin fails to restrict file uploads to authorized users. Furthermore, the plugin does not validate file extensions or contents against \u003ccode\u003eget_allowed_mime_types()\u003c/code\u003e before writing files to the server's uploads directory. This allows authenticated attackers with subscriber-level access or higher to upload malicious, executable files to the web server, which can subsequently be triggered to achieve remote code execution (RCE). This vulnerability poses a significant risk to the integrity and confidentiality of affected WordPress installations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site utilizing vulnerable versions of Use-your-Drive, Out-of-the-Box, Share-one-Drive, or Lets-Box.\u003c/li\u003e\n\u003cli\u003eAttacker obtains subscriber-level access (or leverages the unauthenticated \u003ccode\u003ewp_ajax_nopriv_\u003c/code\u003e exposure) to interact with the plugin's API.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request targeting the \u003ccode\u003edownload_file_to_uploads\u003c/code\u003e function, bypassing the missing \u003ccode\u003ecan_import()\u003c/code\u003e capability check.\u003c/li\u003e\n\u003cli\u003eAttacker provides a remote path to a malicious payload (e.g., a PHP webshell) within the request parameters.\u003c/li\u003e\n\u003cli\u003eThe plugin downloads the file from the remote source without validating against \u003ccode\u003eget_allowed_mime_types()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe file is written to the WordPress \u003ccode\u003euploads\u003c/code\u003e directory with an executable extension.\u003c/li\u003e\n\u003cli\u003eAttacker navigates directly to the uploaded file path via the web browser to trigger code execution.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution to perform system-level operations or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on the underlying web server hosting the WordPress site. This can lead to total site compromise, including the theft of database credentials, defacement, or the installation of persistent backdoors. Affected sectors include any organization hosting WordPress instances with the vulnerable suite of plugins.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box to versions beyond 3.8.3 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests directed to the plugin's API endpoints that result in the creation of executable files (e.g., .php files) within the WordPress \u003ccode\u003euploads\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eImplement strict file upload directory permissions to prevent the execution of scripts in folders where user-supplied content is stored.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts to ensure unauthorized subscriber-level accounts have not been created or used to facilitate this exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T22:11:14Z","date_published":"2026-09-18T22:11:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-cloud-plugins-rce/","summary":"Multiple WP Cloud Plugins for WordPress are vulnerable to arbitrary file upload via the download_file_to_uploads function, enabling remote code execution by authenticated attackers.","title":"Arbitrary File Upload Vulnerability in WP Cloud Plugins for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-cloud-plugins-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Share-One-Drive (2.0 - 3.8.3)","version":"https://jsonfeed.org/version/1.1"}