Impact
A flaw exists in the Blogistic theme that allows an attacker to upload files of any type, bypassing file type restrictions. The vulnerability enables arbitrary file uploads that could be used to store malicious files on the web server. Based on the description, it is inferred that such uploads could result in code execution or other unintended behavior. This issue is classified as CWE‑434, describing unrestricted file uploads that pose severe consequences for confidentiality, integrity, and availability.
Affected Systems
The problem affects the Blogistic theme from version n/a through 1.0.5. The theme is distributed by blazethemes.
Risk and Exploitability
The CVSS score is 9.9, signifying a critical severity, while the EPSS score is less than 1%, indicating a very low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote, requiring an attacker to craft a file upload request to the vulnerable theme’s upload endpoint. A successful exploit could allow the upload of malicious files that might lead to code execution or other unintended behavior, depending on server configuration.
OpenCVE Enrichment