Impact
The vulnerability resides in the WebStack WordPress theme where the io_img_upload() function fails to validate uploaded file types. An attacker can upload any file, including code, which may then be executed on the server, compromising confidentiality, integrity, and availability of the site.
Affected Systems
The issue affects the WebStack theme from Owen, impacting all released versions up to and including 1.2024. WordPress sites using this theme are therefore at risk.
Risk and Exploitability
This flaw carries a CVSS score of 9.8 and is marked as not listed in the CISA KEV catalog. The exploit does not require authentication and can be carried out from any unprivileged network location, making the attack vector accessible to any internet-facing attacker. Opportunity for exploitation is high, and the lack of an availability or isolation countermeasure increases the potential impact.
OpenCVE Enrichment