Arbitrary File Upload Vulnerability in WP Cloud Plugins by WordPress
CVE-2026-93031
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-93031?
The WP Cloud Plugins, including Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box, exhibit a critical flaw allowing arbitrary file uploads. This vulnerability arises from an unsecured import action that permits unauthenticated users to exploit the download_file_to_uploads function. The absence of proper capability checks in can_import() and inadequate file validation against allowed MIME types expose the uploads directory to executable files. As a result, even authenticated users with subscriber access can potentially execute remote code, posing a significant security risk.
Affected Version(s)
Share-one-Drive | OneDrive & SharePoint plugin for WordPress 2.0 <= 3.8.3
Use-your-Drive | Google Drive plugin for WordPress 2.0 <= 3.8.3
WP Cloud Plugins - Box (Lets-Box) 2.0 <= 3.8.3