Impact
The Lendiz theme contains an unrestricted file upload function that accepts dangerous file types. An attacker may upload a web shell file, allowing arbitrary code execution on the web server. This vulnerability falls under CWE‑434 and can lead to complete server compromise.
Affected Systems
This issue affects the WordPress Lendiz theme produced by Zozothemes in all releases prior to 2.0.1. No specific sub‑versions are listed, so any deployment using Lendiz before 2.0.1 is considered vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates maximum severity. The EPSS score of less than 1% suggests a very low current exploitation probability, and the vulnerability is not yet listed in CISA KEV. The description does not detail authentication requirements, so it is inferred that the upload path may be reachable by authenticated users, but the lack of checks on file type greatly increases risk. Exploitation would involve uploading a malicious file via the theme’s interface and then executing it.
OpenCVE Enrichment