Impact
The vulnerability is an unrestricted file upload flaw that allows an attacker to upload any file type to the Wordpress Blogmatic theme. This weakness can enable the injection of executable scripts or other malicious files, potentially leading to remote code execution and full compromise of the hosting server. The defect is identified as CWE‑434, indicating a lack of proper file type validation.
Affected Systems
The flaw affects the blazethemes Blogmatic theme version 1.0.3 and earlier. Users running this theme on any Wordpress installation are at risk unless an updated version is installed.
Risk and Exploitability
The CVSS score of 9.9 signals a high severity impact, yet the EPSS score of less than 1% indicates that, as of now, the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to access the site’s backend or exploit a legitimate file‑upload pathway exposed by the theme; based on the description, the attack vector is inferred to be through the theme’s upload interface, which is not guarded against dangerous file types.
OpenCVE Enrichment