ThemeGoods Photography WordPress Theme Arbitrary File Upload Vulnerability
Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the ThemeGoods Photography WordPress theme, affecting versions through 7.7.5. This vulnerability allows path traversal, which could be exploited to upload malicious files, such as backdoors, that could be executed to gain further access to the website.
Impact
Exploitation of this vulnerability could lead to arbitrary file upload, allowing attackers to upload malicious files that could be executed on the server, potentially leading to a full compromise of the website.
Remediation
Users are advised to update the ThemeGoods Photography WordPress theme to the latest version. If unable to update, consult with your hosting provider or web developer for assistance.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
