CVE-2025-68553

9.9

zozothemes · Lendiz

The zozothemes Lendiz WordPress theme contains an unrestricted file upload vulnerability that allows authenticated users to upload web shells to the web server.

Executive summary

An unrestricted file upload vulnerability in the zozothemes Lendiz WordPress theme allows authenticated attackers to upload malicious files and gain remote code execution.

Vulnerability

This is an unrestricted upload of file with dangerous type (CWE-434) vulnerability. It allows an attacker with authenticated access to bypass file extension restrictions and upload malicious web shells to the server.

Business impact

This vulnerability presents a critical threat to the confidentiality, integrity, and availability of the affected system. Given the high CVSS score, exploitation could result in full server compromise, data theft, and unauthorized modification of the underlying application environment.

Remediation

Immediate Action: Update the Lendiz theme to version 2.0.1 or later to apply the necessary security patches and prevent malicious file uploads.

Proactive Monitoring: Monitor server access logs for requests directed at suspicious file paths or unexpected file types within the WordPress directory structure.

Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect incoming file uploads and block files that contain executable code or unauthorized extensions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Immediate remediation via theme update is required to mitigate the risk of remote code execution. Security teams should prioritize patching this vulnerability to prevent potential unauthorized access and maintain the integrity of their web infrastructure.

More zozothemes CVEs