Junglewise Threat Intelligence

CVE-2024-52488: Zidithemes Grip arbitrary file upload in WordPress theme

CVE-2024-52488 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Executive brief

The Grip theme for WordPress, used for website design and layout, contains a critical security flaw that allows users with basic 'Subscriber' accounts to upload malicious files. This vulnerability can be used by an attacker to gain full control over the website, potentially leading to data theft, site defacement, or the installation of backdoors. As of the latest report, there is no official patch available from the developer.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Grip theme for WordPress through version 1.0.9. The flaw allows an authenticated attacker with low-level 'Subscriber' privileges to upload dangerous file types, such as PHP scripts, to the server. Because the application fails to properly validate or sanitize uploaded files, an attacker can execute arbitrary code in the context of the web server. This can lead to a full site compromise, including arbitrary plugin activation/deactivation and persistent backdoors. No official patch has been released; users are advised to seek alternative themes or use third-party security mitigations.

Affected products

  • Zidithemes Grip <= 1.0.9

Timeline

  • 2024-10-30: other: Vulnerability reported by researcher Mika
  • 2024-11-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References