Junglewise Threat Intelligence

CVE-2026-27419: Zozothemes Zegen arbitrary file upload in WordPress theme

CVE-2026-27419 · Severity: critical · CVSS 9.9 · Published 2026-07-02

Executive brief

The Zegen theme for WordPress, commonly used for church and non-profit websites, contains a critical security flaw that allows registered users to upload malicious files. An attacker with basic subscriber-level access could use this to upload a 'backdoor' script, granting them full control over the website. This could lead to the theft of sensitive data, complete site defacement, or the site being used to spread further malware.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Zozothemes Zegen theme for WordPress in versions up to and including 1.1.9. The flaw allows an authenticated attacker with Subscriber-level privileges to upload dangerous file types, such as PHP scripts, to the server. Because the application fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) by accessing the uploaded file. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • Zozothemes Zegen <= 1.1.9

Timeline

  • 2025-10-28: other: Vulnerability reported by researcher to Patchstack
  • 2026-06-29: advisory: Patchstack published the vulnerability details
  • 2026-07-02: disclosed: CVE published in the National Vulnerability Database (NVD)

References