Impact
Unrestricted upload of files with dangerous types allows an attacker to store a web shell on the target server. The vulnerability, classified as CWE-434, provides an attacker with the ability to execute arbitrary code on the hosting machine, leading to full compromise of the web platform.
Affected Systems
The WordPress Energia theme from Farost, versions from the initial release through 1.1.2, is affected. All installations using these versions are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 10 and an EPSS score of less than 1 percent, indicating a very low likelihood of exploitation in the wild but an extremely high potential impact if targeted. It is not listed in the CISA KEV catalog. The likely attack vector is any user that can access the theme’s upload interface or a user with content‑creation privileges, who can upload a malicious file that the server then executes.
OpenCVE Enrichment