Impact
This vulnerability is an Unrestricted Upload of File with Dangerous Type flaw in the zozothemes Corpkit WordPress theme. An attacker can upload a web shell to the server by submitting a malicious file through the theme’s upload interface. Once uploaded, the web shell can be executed, giving the attacker the ability to run arbitrary code and gain full control over the compromised web server.
Affected Systems
Any installation of zozothemes Corpkit theme version 2.0 or earlier is affected. All users running the theme up to and including version 2.0 are vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical vulnerability. The EPSS score is below 1%, which suggests that exploitation is currently low but still possible. The theme is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote attacker sending a crafted HTTP request that exploits the theme’s file upload functionality, enabling the upload and execution of arbitrary files on the web server.
OpenCVE Enrichment