The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to upload php files leveraging a double extension attack. It's important to note the file is deleted immediately and double extension attacks only work on select servers making this unlikely to be successfully exploited.
CVE ID: CVE-2024-12300
CVSS Base Severity: LOW
CVSS Base Score: 3.7
Vendor: webandprint
Product: AR for WordPress
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 23.34% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)