WordPress AR For WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Web Shell Upload

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the AR For WordPress plugin, affecting versions through 7.98. This vulnerability allows attackers to trick users with higher privileges into uploading a web shell to the server.

Impact

Exploitation could enable the upload of a web shell, potentially leading to unauthorized access or control over the web server.

Added: Sep 26, 2025, 9:38 AM
Updated: Sep 26, 2025, 3:07 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.4
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.