Executive brief
The Appointment theme for WordPress contains a security flaw that could allow an attacker to take over a website. By tricking an administrator into clicking a malicious link or visiting a specific webpage, an attacker can remotely upload a 'web shell' to the server. This gives the attacker full control over the site, allowing them to steal data, modify content, or disrupt operations.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the priyanshumittal Appointment theme for WordPress (versions up to and including 3.7.3). The flaw allows an unauthenticated attacker to perform arbitrary file uploads, specifically web shells, by inducing a logged-in administrator to execute a forged request. This occurs due to insufficient validation of request origins and lack of nonce protection on file upload functionalities. Successful exploitation results in remote code execution (RCE) and full server compromise. The issue is resolved in version 3.7.4.
Affected products
- priyanshumittal Appointment <= 3.7.3
Timeline
- 2026-01-12: other: Vulnerability reported by Trương Hữu Phúc
- 2026-02-11: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published to NVD