What the vulnerability does
01Description
WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.
Explanation of Vulnerability in Simple Terms
02Summary
Peugeot Music version 1.0 contains a missing authentication vulnerability that allows unauthenticated network access to sensitive functionality. An attacker can exploit this without user interaction or special privileges. The vulnerability affects confidentiality, integrity, and availability of the affected system.
What an attacker can do
03Attacker Capabilities
Access sensitive functionality without authentication or credentials.
Potential impact on your site
04Site Impact
Attackers can read, modify, or disrupt the music plugin and potentially the site without logging in.
Conditions required to exploit
05Prerequisites
Network access to the affected Peugeot Music installation; no authentication required.
Key dates
06Disclosure timeline
May 17, 2026
CVE published
May 18, 2026
Record updated