Successful exploitation can turn the restricted upload feature into a remote code execution primitive on the WordPress server. Because the request does not require authentication, a site with the relevant public form can be attacked without first obtaining a user account. Executed code may run with web server privileges and can therefore potentially affect the confidentiality, integrity, and availability of the site or data accessible to that account. The actual privilege boundary, ability to reach other services, and broader organisational impact depend on server configuration, filesystem permissions, and isolation controls. The requirement for a public upload form and the high attack complexity limit applicability, but they do not remove the risk on sites that meet those conditions.