Impact
This vulnerability allows an attacker to upload any file with a dangerous file type to the WordPress Shopo theme. The ability to upload a web shell gives the attacker control over the target web server, allowing remote code execution and full compromise of the site. The flaw is a classic Arbitrary File Upload defect (CWE-434) that bypasses the plugin’s upload validation filters.
Affected Systems
The affected product is the Themify Shopo theme for WordPress. All releases from the initial release through version 1.1.4 are impacted. Versions 1.1.5 and newer are assumed to contain the fix, although site owners should verify against the vendor’s release notes.
Risk and Exploitability
The CVSS score of 9.9 indicates a high‑severity threat, but the EPSS score of less than 1% suggests that attacks are currently infrequent. The vulnerability requires an attacker to exploit the upload interface, which likely necessitates authenticated access to the WordPress administrative area. Because the flaw permits the upload of malicious code, successful exploitation can result in full server compromise, data theft, and defacement. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment