External risk intelligence

Piclect WordPress Plugin Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84171

The vulnerability exists in a WordPress plugin designed for image uploads. WordPress sites are typically public-facing web applications, and functionality that allows unauthenticated file uploads is inherently exposed to the public internet by design.

Unrestricted File Upload

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in the WP images upload feature of a WordPress plugin that could allow unauthorized users to upload and execute malicious files on the server. At a high level, this type of exposure can impact the integrity and availability of web services.

  • Allows arbitrary file uploads and code execution.
  • Matters for basic web application security hygiene.
  • Confirm plugin usage and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by uploading malicious files through the WordPress plugin's image upload feature. Because the plugin does not properly check the name or type of uploaded files before saving them to a public directory, an attacker could upload a web shell. If successful, this could allow the attacker to execute arbitrary code on the server, leading to a complete compromise of the website.

  • No authentication required.
  • Upload arbitrary files to public directory.
  • Arbitrary code execution on server.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could upload arbitrary files to a publicly accessible directory on the server, potentially leading to the execution of arbitrary code. This could impact the integrity and availability of the server.

  • Arbitrary files could be uploaded.
  • Attackers can upload files via the upload function.
  • Server code execution is a potential consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

For this WordPress plugin vulnerability, application owners and infrastructure teams are likely responsible for remediation. The first practical step is to identify all WordPress instances, confirm exposure and criticality, and then assign ownership for planning the fix.

  • Ownership: WordPress application owners.
  • Verify: Public reachability and business criticality.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the piclect WordPress plugin?

The piclect plugin is an extension for WordPress sites used to manage and process image uploads. It provides specific functionality for users to upload image files directly through the website interface, which are then saved to the server's storage for the site to display or process.

What is CWE-434 in the context of CVE-2026-84171?

CWE-434 refers to 'Unrestricted Upload of File with Dangerous Type.' In this CVE, it means the plugin fails to inspect the file type or verify the filename during the upload process. Because the software accepts files without validating that they are legitimate images, it allows attackers to bypass security boundaries and store potentially harmful scripts on the server.

How can an attacker trigger this vulnerability?

An attacker triggers this by interacting with the plugin's upload feature without needing a login or administrative credentials. The vulnerability is not triggered if the plugin is disabled or if the specific image upload function is not reachable. If the function is active, the system blindly accepts whatever file is provided and places it into a directory that is accessible via a web browser.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates this is a high-priority concern because the plugin's core purpose—handling public image uploads—naturally places it on the public-facing side of your infrastructure. Since the software allows unauthenticated access to this function by design, it is inherently exposed to the internet, increasing the likelihood that it could be identified and misused.

How do I respond if I am running this plugin?

Begin by confirming whether your WordPress instances are currently using the affected piclect plugin versions. Once identified, evaluate the necessity of the plugin against the risk of arbitrary code execution. Immediately restrict access to the upload function if possible, and prioritize planning a remediation path with your site administrators to address the security gap.

References