All verified exploits

CVE-2026-1555 WebStack Theme Unauthenticated Arbitrary File Upload

Deterministic critical WordPress Added cve-verified-cve-2026-1555

Detects the WebStack WordPress theme through version 1.2024 where the io_img_upload() function in inc/ajax.php is registered on wp_ajax_nopriv (no authentication) and declares an allowed extension list ('jpg','png','jpeg') but never enforces it. An unauthenticated attacker can POST any file — including PHP — to admin-ajax.php with action=img_upload and the file is saved into the WordPress uploads directory with its original extension, enabling remote code execution. The vendor is unmaintained and no patch exists; remove the theme or block the endpoint.

Related WordPress exploits

Is your app exploitable through CVE-2026-1555?

Scan your domain free