CVE WATCH / VULNERABILITY DETAIL

CVE-2026-75873

CRITICALCVSS 9.8NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-75873 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-75873

CRITICALCVSS 9.8NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]