Critical Vulnerability in Zella Theme WordPress Theme Allows Remote Code Execution
A critical vulnerability (CVE-2026-75873) with a CVSS score of 9.8 affects the Zella Theme WordPress theme before version 2.6.3. An unauthenticated attacker can exploit this vulnerability to upload arbitrary files, including PHP ones, and achieve remote code execution. Immediate action is required to update to version 2.6.3 or later.