Impact
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event theme allows an attacker to upload arbitrary files, including executable code such as PHP scripts. Once an attacker successfully uploads a malicious file, they can execute it on the web server, potentially taking full control of the WordPress installation. The weakness is a classic input validation flaw (CWE‑434).
Affected Systems
WordPress sites that use the News Event theme version 1.0.1 or earlier are affected. Any installation where this theme is active and has the upload feature enabled must be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical level of severity, and the EPSS score of less than 1% suggests low exploitation probability at present, although the vulnerability is not listed as a known exploit in the CISA KEV catalog. The most likely attack vector is through the theme’s administrator‑side upload interface, which appears to lack proper type validation or permission checks. An attacker with access to that interface could exploit the flaw without additional prerequisites.
OpenCVE Enrichment