CVE-2026-84171
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 12, 2026
Vendor
unknown
Description
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.