What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 6.6.
Explanation of Vulnerability in Simple Terms
02Summary
The AR For WordPress plugin versions 6.6 and earlier contain an unrestricted file upload vulnerability. An attacker can upload arbitrary files to the site without authentication, potentially allowing them to run malicious code, modify site content, or take full control of the WordPress installation. This is a critical vulnerability affecting all installations of the plugin.
What an attacker can do
03Attacker Capabilities
Upload arbitrary files and run malicious code on the site without needing to log in.
Potential impact on your site
04Site Impact
Complete compromise of the WordPress site, including data theft, malware injection, and loss of site control.
Conditions required to exploit
05Prerequisites
None. The attacker can exploit this remotely over the network without authentication or user interaction.
Key dates
06Disclosure timeline
October 28, 2024
CVE published
May 11, 2026
Record updated