What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web Shell to a Web Server.This issue affects Zita Elementor Site Library: from n/a through 1.6.1.
Explanation of Vulnerability in Simple Terms
02Summary
Zita Elementor Site Library versions up to 1.6.1 allow authenticated users to upload files without proper validation. An attacker with low-level site access can upload malicious files, including PHP scripts, to execute code on the server. This affects confidentiality, integrity, and availability of the entire site.
What an attacker can do
03Attacker Capabilities
Upload and execute malicious files (including PHP code) on the server to compromise the site.
Potential impact on your site
04Site Impact
Compromised site with potential data theft, malware injection, or complete takeover via uploaded code execution.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account on the site (subscriber or contributor level).
Key dates
06Disclosure timeline
July 9, 2024
CVE published
April 28, 2026
Record updated