WordPress Theme Travelscape 1.0.3 Arbitrary File Upload
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
WP Travel Kit · Travelscapepublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/51969unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.