Junglewise Threat Intelligence

CVE-2026-40747: themagnifico52 Ecommerce Zone arbitrary file upload

CVE-2026-40747 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Vendors: Themagnifico52.

Executive brief

The Ecommerce Zone theme for WordPress, used for building online stores, contains a critical security flaw that allows users with basic 'Subscriber' accounts to upload malicious files. An attacker could use this to upload a web shell or backdoor, effectively taking full control of the website. This could lead to the theft of customer data, site defacement, or a total service outage.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Ecommerce Zone theme for WordPress in versions up to and including 0.9.7. The flaw allows an authenticated attacker with Subscriber-level permissions to upload files with dangerous extensions, such as .php, to the server. Because the application fails to properly validate the file type or content, an attacker can achieve remote code execution (RCE) by accessing the uploaded file. This vulnerability has a CVSS score of 9.9 due to the potential for full system compromise and the low privilege requirement. A fix is available in version 0.9.8.

Affected products

  • themagnifico52 Ecommerce Zone <= 0.9.7

Timeline

  • 2026-02-22: other: Vulnerability reported by Denver Jackson
  • 2026-04-20: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-06-17: patched: Version 0.9.8 released to address the issue

References