CRITICAL 9.8 NVD
CVE-2026-75873
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthentic
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
References
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-30 via NVD.
Risk Timeline
CVE Disclosed2026-09-30 · -1 days ago
Remediation Resources
Official Advisory
wpscan.com/vulnerability/15b8a6cb-f89c-4d4d-9812-441e822c647f/
vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.