Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-54352 2 Wordpress, Wp Travel Kit 2 Wordpress, Travelscape 2026-06-09 9.8 Critical
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and upload additional files for persistent access.
CVE-2024-58349 2 Wordpress, Wp Travel Kit 2 Wordpress, Travelscape 2026-06-09 9.8 Critical
WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.