Detects the WebStack WordPress theme through version 1.2024 where the io_img_upload() function in inc/ajax.php is registered on wp_ajax_nopriv (no authentication) and declares an allowed extension list ('jpg','png','jpeg') but never enforces it. An unauthenticated attacker can POST any file — including PHP — to admin-ajax.php with action=img_upload and the file is saved into the WordPress uploads directory with its original extension, enabling remote code execution. The vendor is unmaintained and no patch exists; remove the theme or block the endpoint.
Is your app exploitable through CVE-2026-1555?
Scan your domain free