Impact
Unrestricted upload of files with dangerous types is possible in the Charety theme. This flaw allows an attacker to place malicious payloads on the server, potentially enabling remote code execution and full compromise of the WordPress site. The weakness is identified as CWE‑434, indicating that improper validation of the file type during the upload process is the root cause.
Affected Systems
The vulnerability affects the Charety theme released by zozothemes. All versions from the initial release up to, but not including, 2.0.2 are impacted. Any site currently running a vulnerable theme version is at risk.
Risk and Exploitability
The CVSS score of 9.9 classifies this issue as critical, and the EPSS score of less than 1 % suggests a low but non‑zero likelihood of exploitation at the time of analysis. The theme is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote, acting through the theme’s public upload interface—any user able to reach this interface can upload a file that may be executed by the site.
OpenCVE Enrichment