Executive brief
The Busiprof theme for WordPress contains a security flaw that could allow an attacker to take over a website. By tricking a site administrator into clicking a malicious link or visiting a specially crafted webpage, the attacker can force the website to upload a 'web shell.' This malicious file gives the attacker full control over the web server, potentially leading to data theft, site defacement, or further attacks on the organization's infrastructure.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the priyanshumittal Busiprof theme for WordPress (versions up to and including 2.5.4). The vulnerability stems from a lack of nonce validation or insufficient request verification during file upload operations. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to upload arbitrary files, such as a PHP web shell, to the web server. This leads to remote code execution (RCE) and full system compromise. As of the advisory date, no official patch is available, and users are advised to replace the theme.
Affected products
- priyanshumittal Busiprof <= 2.5.2 (NVD); <= 2.5.4 (Patchstack)
Timeline
- 2026-01-12: other: Vulnerability reported by Trương Hữu Phúc
- 2026-02-11: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD