External risk intelligence

Corpkit Theme Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2025-67924

The vulnerability affects a WordPress theme, which is a component of a web application. WordPress sites are frequently deployed as internet-facing web services, and theme-based file upload functionality is typically accessible through the web interface, making the attack surface commonly exposed to the internet.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts a component used in web applications, specifically a theme that allows file uploads. If exploited, an attacker could upload malicious code to a web server, potentially leading to unauthorized control. The primary concern is to determine if this specific component is in use within our environment and if it's exposed externally.

  • Allows uploading malicious code to servers.
  • Affects web applications; confirm relevance and exposure.
  • Prioritize verifying use and external access.

Attack Path

How an attacker could exploit the issue

An attacker with low-privilege access to a web server running Corpkit could upload a malicious web shell. This web shell would then allow the attacker to gain control of the server.

  • Requires authenticated access.
  • Upload a web shell file.
  • Enables remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated user to upload a web shell to a web server. This can occur when the affected theme is used on a web application and its file upload functionality is accessible.

  • Server code execution.
  • Uploading a malicious file.
  • Compromised web server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The "Corpkit" theme for WordPress, specifically versions up to and including 2.0, is affected by an unrestricted file upload vulnerability that could allow for the deployment of a web shell. This typically falls under the responsibility of the web application owner or the platform team managing the WordPress instance. The immediate priority is to locate all instances of this theme, assess their exposure, and confirm business criticality before planning remediation, which may involve vendor coordination.

  • Application owners should own this issue.
  • Verify theme version and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Corpkit theme?

Corpkit is a theme designed for WordPress, a content management system used to build and maintain websites. Themes like Corpkit control the visual layout, styling, and some functional features of a site. In this context, it acts as a modular component that extends the core WordPress platform to provide specific design capabilities for site administrators.

What does CVE-2025-67924 mean by unrestricted file upload?

This vulnerability is classified as CWE-434, which occurs when a system fails to properly validate the type or contents of files uploaded by a user. Because the application does not restrict what is sent to the server, an attacker can bypass security checks to upload a malicious file, such as a web shell, which can then be executed by the server.

How does an attacker trigger this vulnerability?

An attacker needs low-privilege access to the web server to initiate the upload process. The vulnerability is triggered when the application accepts a malicious file through the theme's upload feature without verification. It is important to note that simply visiting the site or viewing a page does not trigger this; the attacker must be able to interact with the specific file upload function provided by the theme.

Is my site at risk if it uses Corpkit?

According to Halo Surface Signal, this vulnerability is highly relevant for most users. Because WordPress sites are commonly deployed as internet-facing services, the file upload functionality in themes is often directly exposed to the public web. If your instance is accessible from the internet, the potential for an external attacker to interact with the vulnerable component is significantly increased.

What should I do first if I use this WordPress theme?

The immediate priority is to conduct an inventory to identify all instances of the Corpkit theme within your environment. Once identified, confirm the version in use to see if it is 2.0 or earlier. After confirming presence and versioning, assess the specific web application's exposure and coordinate with your web platform team to plan for updates or removal of the theme to mitigate the risk.

References