Impact
An attacker who can act as a site subscriber can submit arbitrary files through the WordPress Travel Booking Theme’s upload functionality. Because the theme’s upload validation is insufficient, any file type, including executable scripts, can be stored on the web server. The CVE wording does not confirm that these files will be automatically executed, but the presence of a writable upload path that accepts executable code is a well‑known vector for remote code execution. If a script is executed, the attacker could compromise the confidentiality, integrity, and availability of the entire WordPress site.
Affected Systems
The vulnerability is present in the WordPress Travel Booking Theme distributed by PhysCode, affecting version 2.2.5 and all earlier releases. Any WordPress site using these theme versions could be impacted if the upload feature is exposed to subscriber accounts.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, and the vulnerability is listed in KEV as not exploited. The EPSS score is not available, so the current exploitation probability is unknown. Based on the description, it is inferred that the attack vector involves a web‑based file upload form accessible to subscribers. If execution occurs, the flaw could lead to remote code execution, placing the affected site at substantial risk.
OpenCVE Enrichment