WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
criticalThe WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote co...
- CVSS:
- 9.8
- Affected:
- up to 1.2024
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2026