What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
Explanation of Vulnerability in Simple Terms
Themify Ultra versions up to 7.3.5 do not properly validate file uploads, allowing authenticated users to upload arbitrary files to the site. An attacker with low-level access can upload malicious files—such as PHP scripts—that execute on the server. This grants the attacker full control over the site's content, data, and functionality.
What an attacker can do
Upload and execute arbitrary files (e.g., PHP scripts) on the site server.
Potential impact on your site
Compromised site with potential data theft, malware injection, and complete loss of control.
Conditions required to exploit
Attacker must have a low-level user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities