WordPress Plugin Peugeot Music Arbitrary File Upload Vulnerability

Vulnerability

An arbitrary file upload vulnerability has been identified in WordPress Plugin Peugeot Music version 1.0. This vulnerability allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Exploitation involves manipulating the 'name' parameter to upload files with arbitrary extensions, which can then be executed from the uploads directory.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, allowing attackers to execute malicious files on the server.

Reproduction

To reproduce this vulnerability, send a POST request to the upload.php endpoint within the Peugeot Music plugin directory. Include a file in the 'file' parameter and manipulate the 'name' parameter to give the file an executable extension, such as .php. The uploaded file will be accessible from the uploads directory, where it can be executed on the server.

Added: May 17, 2026, 1:22 PM
Updated: May 17, 2026, 1:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
8.6
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.