The GREYD.SUITE WordPress theme does not properly...
Critical severity
Unreviewed
Published
Aug 16, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Aug 15, 2022
Published to the GitHub Advisory Database
Aug 16, 2022
Last updated
Jan 28, 2023
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).
References