Executive brief
Charity Zone, a WordPress theme designed for charitable organizations, contains a security flaw that allows registered users with low-level 'Subscriber' permissions to upload malicious files. An attacker could use this to upload a 'backdoor' script, granting them full control over the website. This could lead to the theft of donor data, website defacement, or the complete shutdown of the organization's online presence.
Technical details
The Charity Zone theme for WordPress (versions 1.1.1 and below) suffers from an unrestricted file upload vulnerability (CWE-434). The flaw allows an authenticated attacker with Subscriber-level privileges to upload files of dangerous types, such as PHP scripts, to the web server. This occurs due to insufficient validation of file extensions or content during the upload process. Successful exploitation enables remote code execution (RCE), allowing the attacker to compromise the underlying server or the WordPress environment. The issue is addressed in version 1.1.2.
Affected products
- themagnifico52 Charity Zone <= 1.1.1
Timeline
- 2026-02-22: other: Vulnerability reported by Denver Jackson
- 2026-04-20: advisory: Patchstack published advisory
- 2026-06-17: disclosed: NVD publication date