Impact
The IT Residence theme for WordPress contains an arbitrary file upload flaw that permits a subscriber to upload any file type. The flaw arises from a lack of file type validation and sanitization during the upload process. An attacker who can authenticate as a subscriber could therefore upload a malicious script or executable file, potentially achieving remote code execution or compromising the integrity of the WordPress site.
Affected Systems
This vulnerability affects the IT Residence theme supplied by Indithemes. Versions 3.2.1 and all earlier releases are impacted. Sites that use this theme and enable the subscriber feature are likely affected.
Risk and Exploitability
The CVSS score of 9.9 indicates a severe risk with the potential for remote code execution. While the EPSS score is not available, making the exact exploitation likelihood uncertain, the high score underscores that the flaw can be exploited by any user with subscriber privileges. The vulnerability is not listed in CISA KEV, suggesting no confirmed wild exploitation at present, yet the combination of high severity and an authenticated attack vector warrants immediate attention.
OpenCVE Enrichment