Junglewise Threat Intelligence

CVE-2026-40748: themagnifico52 Kids Gift Shop arbitrary file upload

CVE-2026-40748 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Vendors: Themagnifico52.

Executive brief

The Kids Gift Shop theme for WordPress contains a critical security flaw that allows registered users with low-level 'Subscriber' permissions to upload malicious files to the server. This could allow an attacker to take complete control of the website, steal sensitive customer data, or disrupt business operations. The vulnerability is particularly dangerous as it can be used to install 'backdoors' for persistent access.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Kids Gift Shop theme for WordPress in versions up to and including 0.5.4. The flaw allows an authenticated attacker with Subscriber-level permissions to upload files with dangerous extensions, such as .php, to the web server. Because the application fails to properly validate the file type or content, an attacker can achieve remote code execution (RCE) and full site compromise. The vulnerability has been addressed in version 0.5.5.

Affected products

  • themagnifico52 Kids Gift Shop <= 0.5.4

Timeline

  • 2026-02-22: other: Reported by Denver Jackson
  • 2026-04-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD published date
  • 2026-06-17: patched: Patch confirmed available in version 0.5.5

References