Description
Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a Web Server.This issue affects Medcity: from n/a through < 1.1.9.
Published: 2025-10-22
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unrestricted file upload flaw that allows an attacker to upload files with dangerous types, such as PHP web shells, to a WordPress site using the 7oroof Medcity theme. This flaw gives the attacker the ability to execute arbitrary code on the web server, compromising confidentiality, integrity, and availability of the site and any data it hosts, and potentially allowing full system control. The weakness is identified as CWE‑434.

Affected Systems

All installations of the 7oroof Medcity WordPress theme running a version earlier than 1.1.9 are affected. Users who have not upgraded to 1.1.9 or later are at risk. The issue is limited to this theme within the WordPress ecosystem.

Risk and Exploitability

The CVSS base score of 10 highlights the maximum severity of this flaw. With an EPSS score of less than 1% the likelihood of exploitation in the wild is currently low, yet the impact remains catastrophic. The vulnerability is not yet cataloged in CISA&#x27;s KEV program. Based on the description, it is inferred that the attack vector is via the theme’s upload functionality, which may be limited to users with certain WordPress roles but can be exploited through any available upload path by submitting a malicious file that bypasses MIME type checks, giving the attacker the ability to execute arbitrary code.

Generated by OpenCVE AI on April 30, 2026 at 05:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Medcity theme to version 1.1.9 or newer to apply the vendor fix.
  • Verify that all theme files from older versions have been removed and that no residual files remain on the server.
  • Configure WordPress to restrict uploaded file types to images or text only by adjusting the allowed MIME types in wp-config.php or using a security plugin, thereby preventing future arbitrary file uploads.

Generated by OpenCVE AI on April 30, 2026 at 05:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a Web Server.This issue affects Medcity: from n/a through < 1.1.9.
Title WordPress Medcity theme < 1.1.9 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:50.417Z

Reserved: 2025-09-06T04:45:10.578Z

Link: CVE-2025-58963

cve-icon Vulnrichment

Updated: 2025-10-23T13:40:53.308Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:52.830

Modified: 2026-04-27T20:16:22.830

Link: CVE-2025-58963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:45:16Z

Weaknesses