Themes Vulnerabilities

Multiple themes - Unauthenticated Arbitrary File Upload

Description

Multiple themes from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

Proof of Concept

Affects Themes

Fixed in 2.1
No known fix
No known fix
No known fix
No known fix
No known fix
No known fix
No known fix
No known fix
No known fix

References

Classification

Type
RCE
OWASP top 10
CWE

Miscellaneous

Original Researcher
Joshua Small
Submitter
Joshua Small
Verified
Yes

Timeline

Publicly Published
2022-12-29 (about 3 years ago)
Added
2022-12-29 (about 3 years ago)
Last Updated
2022-12-29 (about 3 years ago)

Other