CVE-2026-84171: Unknown Wp Images Upload On Piclect

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

Affected products

  • Unknown Wp Images Upload On Piclect: up to and including 1.0

Published 2026-09-12. Last modified 2026-09-14.