Junglewise Threat Intelligence

CVE-2026-40750: themagnifico52 Kids Online Store arbitrary file upload in WordPress theme

CVE-2026-40750 · Severity: critical · CVSS 9.9 · Published 2026-06-16

Vendors: Themagnifico52.

Executive brief

The Kids Online Store theme for WordPress contains a critical security flaw that allows users with low-level accounts to upload malicious files to the web server. An attacker can use this to install a 'web shell,' giving them full control over the website and its data. This could lead to a complete site takeover, theft of customer information, or the site being used to host further attacks.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the themagnifico52 Kids Online Store theme for WordPress through version 0.8.9. The flaw allows an authenticated user, even with low-level 'Subscriber' privileges, to upload files with dangerous extensions (such as .php) to the server. Because the application fails to properly validate file types or contents, an attacker can upload and execute a web shell. This results in remote code execution (RCE) and potential full system compromise. The issue is resolved in version 0.9.0.

Affected products

  • themagnifico52 Kids Online Store <= 0.8.9

Timeline

  • 2026-02-22: other: Vulnerability reported by Denver Jackson
  • 2026-04-20: advisory: Patchstack published advisory details
  • 2026-04-20: patched: Version 0.9.0 released to address the vulnerability
  • 2026-06-16: disclosed: CVE-2026-40750 published to the NVD dataset

References