Executive brief
IT Residence is a WordPress theme used to build and customize WordPress websites. A vulnerability in versions 3.2.1 and earlier allows attackers with subscriber-level access to upload malicious files to the server, potentially enabling complete site takeover and deployment of malware or ransomware to all visitors.
Technical details
The IT Residence WordPress theme contains an arbitrary file upload vulnerability requiring only subscriber-level privileges to trigger. The vulnerability allows unauthenticated or low-privileged users to bypass file type validation and upload malicious executable files to the web server. No official patch has been released; Patchstack has implemented a mitigation rule to block attack attempts. The vulnerability is expected to see widespread exploitation due to its high severity and ease of exploitation.
Affected products
- IT Residence IT Residence <= 3.2.1
Timeline
- 2026-08-20: disclosed
- 2026-08-20: advisory: Patchstack issued mitigation rule; no official patch available
- 2026-02-22: other: Vulnerability initially reported by Denver Jackson