Wordpress Alert: Executable files disguised as images

An upload accepts a file based only on its name or claimed content type. A script may be stored where it can be executed or served to visitors.

What it looks like

An upload accepts a file based only on its name or claimed content type.

Why it matters

A script may be stored where it can be executed or served to visitors.

What to check

Verify actual file type and prevent execution in upload storage.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP file upload guidance.