A critical vulnerability (CVSS Score: 9.9) was discovered in the Charity Zone WordPress theme, version 1.1.1 and below. The vulnerability allows subscribers to upload arbitrary files, potentially leading to severe consequences. This issue was made public on June 17, 2026. Users of the affected theme should take immediate action to mitigate the risk.
A critical vulnerability was discovered in the Kids Gift Shop WordPress theme version 0.5.4 and earlier. This vulnerability allows subscribers to upload arbitrary files, potentially leading to severe consequences, including code execution and compromise of the affected system. The vulnerability has a CVSS score of 9.9 and is considered critical. The issue was publicly disclosed on June 17, 2026.
A critical vulnerability was found in Ecommerce Zone version <= 0.9.7. This vulnerability allows subscribers to upload arbitrary files, potentially leading to serious security issues such as code execution, data breaches, or system compromise. The vulnerability has a CVSS score of 9.9 and is classified as CRITICAL. Users of Ecommerce Zone version <= 0.9.7 should be aware of this vulnerability and take nec [truncated]
A critical vulnerability was discovered in the Restaurant Zone theme for WordPress, allowing subscribers to upload arbitrary files. This vulnerability has a CVSS score of 9.9 and was published on June 17, 2026. The vulnerability affects versions of the theme up to and including 0.7.8. Successful exploitation could allow an attacker to upload malicious files, potentially leading to code execution or other [truncated]
A critical vulnerability was discovered in the Kids Online Store theme, affecting versions from n/a through 0.8.9. This vulnerability, classified as CWE-434, allows for the unrestricted upload of files with dangerous types, potentially enabling attackers to upload a web shell to a web server. The vulnerability has a CVSS score of 9.9 and is considered critical.