Junglewise Threat Intelligence

CVE-2026-22327: Zozothemes Restaurt arbitrary file upload

CVE-2026-22327 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Executive brief

The Restaurt theme for WordPress, used for restaurant and food service websites, contains a critical security flaw that allows registered users with low-level 'Subscriber' permissions to upload malicious files. An attacker could use this to upload a 'backdoor' script, granting them full control over the website. This could lead to the theft of customer data, website defacement, or the complete shutdown of the online service.

Technical details

The Restaurt theme for WordPress (versions 1.0.4 and below) suffers from an unrestricted file upload vulnerability (CWE-434). The flaw allows an authenticated attacker with Subscriber-level privileges to upload files with dangerous extensions (such as .php) to the server. Because the theme fails to properly validate the type or content of uploaded files, an attacker can achieve remote code execution (RCE) by accessing the uploaded script. This vulnerability has a high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.9. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • Zozothemes Restaurt <= 1.0.4

Timeline

  • 2025-09-16: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2026-01-13: advisory: Initial disclosure by Patchstack
  • 2026-06-17: disclosed: CVE published to NVD

References