Arbitrary File Upload Vulnerability in WP Cloud Plugins by WordPress
CVE-2026-93031

8.8HIGH

What is CVE-2026-93031?

The WP Cloud Plugins, including Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box, exhibit a critical flaw allowing arbitrary file uploads. This vulnerability arises from an unsecured import action that permits unauthenticated users to exploit the download_file_to_uploads function. The absence of proper capability checks in can_import() and inadequate file validation against allowed MIME types expose the uploads directory to executable files. As a result, even authenticated users with subscriber access can potentially execute remote code, posing a significant security risk.

Affected Version(s)

Share-one-Drive | OneDrive & SharePoint plugin for WordPress 2.0 <= 3.8.3

Use-your-Drive | Google Drive plugin for WordPress 2.0 <= 3.8.3

WP Cloud Plugins - Box (Lets-Box) 2.0 <= 3.8.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

WP Cloud Plugins
.