What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through <= 1.1.4.
Explanation of Vulnerability in Simple Terms
02Summary
ACF Images Search And Insert versions up to 1.1.4 allow authenticated users to upload files without proper validation. An attacker with low-level site access can upload malicious files, including executable code, to gain full control of the site. The vulnerability affects all versions from 0 to 1.1.4.
What an attacker can do
03Attacker Capabilities
Upload malicious files and run arbitrary code on the site.
Potential impact on your site
04Site Impact
Complete site compromise: attackers can modify content, steal data, or take the site offline.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account (e.g., contributor or subscriber role).
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 28, 2026
Record updated