PT-2026-103024 · WordPress · Zella Theme
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zella Theme versions prior to 2.6.3
Description
An unrestricted file upload issue exists in the Zella Theme for WordPress. The software fails to perform capability or nonce checks on a font upload action, which is accessible to unauthenticated users. This allows an attacker to upload arbitrary files, such as PHP scripts, leading to remote code execution (RCE), which is the ability to execute arbitrary commands on the server.
Recommendations
Update Zella Theme to version 2.6.3 or later.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zella Theme