rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.7 · EPSS 0.00516

CVE-2026-105123

A critical remote code execution flaw exists in Vincent Peugnet's WCMS (v3.18.0) that lets authenticated editors upload arbitrary files via

Overview

A critical remote code execution flaw exists in Vincent Peugnet's WCMS (v3.18.0) that lets authenticated editors upload arbitrary files via the media upload API. The vulnerability allows path traversal to write files outside the media directory and delete arbitrary files, enabling execution of malicious PHP code. This flaw can be exploited by anyone with editor credentials to compromise the web server.

Description

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path].

Impact

Confidentiality: attackers can read or modify any file on the server. Integrity: arbitrary files can be created, overwritten, or deleted, including web application code. Availability: malicious code execution may crash services or open backdoors. Defenders are the site administrators and security teams managing WCMS installations.

Remediation

Apply the official patch to WCMS 3.18.1 or later. If patching is delayed, restrict the media upload endpoint to allow only image MIME types and enforce strict path validation. Disable PHP execution in the media directory via web server configuration (e.g., AddType application/x-httpd-php .php to a .htaccess file that denies execution). Use a web application firewall to block suspicious POST/DELETE requests to /api/v0/media/* and monitor for anomalous file changes.

Risk context

The CVSS v3 score of 8.8 and EPSS of 0.00516 indicate a high severity but low likelihood of widespread exploitation. Immediate patching is recommended for any WCMS 3.18.0 installations, especially those exposed to the internet or with editor accounts.

Affected products

  • Vincent Peugnet WCMS
  • WCMS 3.18.0
  • WCMS 3.x

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
8.7
EPSS
0.00516

remote-code-execution file-upload authenticated web-application critical media-upload

← All CVEs