Executive brief
The Restaurant Zone theme for WordPress, used to create websites for food and dining businesses, contains a critical security flaw. An attacker with a basic user account (such as a subscriber) can upload malicious files to the web server. This could allow them to take complete control of the website, steal sensitive data, or disrupt business operations.
Technical details
The Restaurant Zone theme for WordPress (versions up to and including 0.7.8) is vulnerable to an Unrestricted Upload of File with Dangerous Type (CWE-434). The flaw allows an authenticated attacker with 'Subscriber' level privileges to upload arbitrary files, such as PHP scripts, to the server. Because the application fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) by accessing the uploaded file. This vulnerability has a high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.9. A patch is available in version 0.7.9.
Affected products
- themagnifico52 Restaurant Zone <= 0.7.8
Timeline
- 2026-02-22: other: Reported by Denver Jackson
- 2026-04-20: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date
- 2026-04-20: patched: Version 0.7.9 released to address the vulnerability