Description
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Published: 2026-08-20
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IT Residence theme for WordPress contains an arbitrary file upload flaw that permits a subscriber to upload any file type. The flaw arises from a lack of file type validation and sanitization during the upload process. An attacker who can authenticate as a subscriber could therefore upload a malicious script or executable file, potentially achieving remote code execution or compromising the integrity of the WordPress site.

Affected Systems

This vulnerability affects the IT Residence theme supplied by Indithemes. Versions 3.2.1 and all earlier releases are impacted. Sites that use this theme and enable the subscriber feature are likely affected.

Risk and Exploitability

The CVSS score of 9.9 indicates a severe risk with the potential for remote code execution. While the EPSS score is not available, making the exact exploitation likelihood uncertain, the high score underscores that the flaw can be exploited by any user with subscriber privileges. The vulnerability is not listed in CISA KEV, suggesting no confirmed wild exploitation at present, yet the combination of high severity and an authenticated attack vector warrants immediate attention.

Generated by OpenCVE AI on August 20, 2026 at 20:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the IT Residence theme to a version newer than 3.2.1 that includes the fixed upload validation.
  • Restrict subscriber uploads to permitted file types, such as only images, and reject all executable or script files.
  • Disable the subscriber upload feature until the theme is updated to eliminate the vulnerability.

Generated by OpenCVE AI on August 20, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Title WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:27.358Z

Reserved: 2026-08-14T10:16:17.543Z

Link: CVE-2026-74014

cve-icon Vulnrichment

Updated: 2026-08-20T16:19:08.589Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:37.187

Modified: 2026-08-20T17:19:41.877

Link: CVE-2026-74014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:45:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type