Executive Summary

A critical vulnerability (CVE-2026-75873) with a CVSS score of 9.8 affects the Zella Theme WordPress theme before version 2.6.3. This vulnerability allows an unauthenticated attacker to upload arbitrary files, including PHP ones, and achieve remote code execution. The vulnerability has not been actively exploited but requires immediate attention to update to version 2.6.3 or later.

Technical Analysis

The vulnerability is classified as CWE-434, which involves an Unrestricted Upload of File with Dangerous Type. The Zella Theme WordPress theme before version 2.6.3 does not perform any capability or nonce check on one of its font upload actions. This action is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.

How It Gets Exploited

An unauthenticated remote attacker can exploit this vulnerability by sending a crafted request to the font upload action. The attacker would not need any specific privileges or user interaction. Upon triggering the vulnerability, the attacker can upload a malicious PHP file, which can then be executed on the server, achieving remote code execution as the web service user. This could allow the attacker to pivot to internal databases or further compromise the system.

Impact Assessment

The Zella Theme WordPress theme before version 2.6.3 is affected. An attacker can achieve remote code execution, which has a high impact on confidentiality, integrity, and availability. The CVSS score of 9.8 indicates a critical severity level.

Recommended Actions

To mitigate this vulnerability, update the Zella Theme WordPress theme to version 2.6.3 or later. Additionally, implement proper file upload validation and restrictions to prevent similar attacks. Monitor for any suspicious file upload activities and ensure that the WordPress environment is properly secured.

Sources

- National Vulnerability Database (NVD) - WPScan