CVE-2016-20075

HIGH

WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20075. PoCs published by i0akiN SEC-LABORATORY.

AI-analyzed exploit summary This is a technical writeup detailing an arbitrary file upload vulnerability in WordPress Ultimate Product Catalogue Plugin v3.8.6. The vulnerability allows authenticated users to upload malicious files due to insufficient file extension checks in the `UPCP_Handle_File_Upload` function.

Description

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file field and access them via the upcp-product-file-uploads directory to execute arbitrary code on the server.

Exploits (1)

exploitdb WRITEUP
by i0akiN SEC-LABORATORY · textwebappsphp
https://www.exploit-db.com/exploits/40012

This is a technical writeup detailing an arbitrary file upload vulnerability in WordPress Ultimate Product Catalogue Plugin v3.8.6. The vulnerability allows authenticated users to upload malicious files due to insufficient file extension checks in the `UPCP_Handle_File_Upload` function.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Ultimate Product Catalogue Plugin v3.8.6
Auth required
Prerequisites: Authenticated user with contributor/editor/author/administrator privileges · Plugin installed and configured
devstral-2 · analyzed Jun 15, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-40012
https://www.exploit-db.com/exploits/40012
Product product
Official Product Homepage
http://www.EtoileWebDesign.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
https://www.vulncheck.com/advisories/wordpress-ultimate-product-catalog-arbitrary-file-upload-rce

Scores

CVSS v3 8.8
EPSS 0.0033
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
Etoilewebdesign/Ultimate Product Catalog 3.8.6
Published Jun 15, 2026
Tracked Since Jun 15, 2026