External risk intelligence

Zella Theme Unauthenticated Arbitrary File Upload Leading to Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75873

This vulnerability affects a WordPress theme, which is a component of a web application. WordPress sites are frequently deployed as public-facing web applications, making the theme's functionality, including file upload features, commonly accessible via the internet.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability relates to a popular WordPress theme that allows unauthenticated users to upload malicious files, potentially leading to unauthorized code execution on affected websites. The core issue is the lack of proper security checks on file uploads, making it a significant concern for any organization using this theme.

  • Unauthenticated users can upload harmful files.
  • Websites using this theme are at risk of compromise.
  • Confirm relevance and exposure to maintain security.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by accessing a WordPress site that uses the Zella theme. The theme's font upload feature, which lacks proper security checks, can be directly accessed by anyone on the internet. This allows an unauthenticated user to upload malicious files, such as PHP scripts, enabling them to execute code on the server.

  • No authentication required to access.
  • Unprotected font upload feature.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated users to upload arbitrary files, including executable PHP files, to a WordPress site. When this file upload action is supported by the advisory, it could lead to the execution of malicious code on the server, potentially impacting the website's operation and integrity.

  • WordPress theme files.
  • Unauthenticated file uploads.
  • Remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Zella Theme for WordPress allows unauthenticated users to upload arbitrary files, including PHP, leading to remote code execution. Website owners, application administrators, and potentially infrastructure or security teams responsible for WordPress deployments must act. The immediate first step is to identify all instances of the Zella Theme, assess their reachability and business criticality, confirm ownership, and then prioritize remediation based on risk.

  • Website owners and administrators own this issue.
  • Verify theme's presence and exposure first.
  • Plan remediation based on business impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Zella Theme for WordPress?

The Zella Theme is a software component designed for the WordPress content management system that modifies the appearance and layout of a website. Themes often include specialized functional features, such as custom font uploaders, which allow site administrators to extend the visual design. Because this theme manages site presentation, it is integrated directly into the WordPress environment and interacts with server-side file handling processes.

What does CWE-434 mean regarding CVE-2026-75873?

CWE-434 refers to an Unrestricted Upload of File with Dangerous Type. In the context of this CVE, it means the software lacks necessary safeguards when processing new files. Because the theme fails to verify who is uploading a file or what type of file is being submitted, the system can be tricked into accepting dangerous scripts instead of legitimate font files, ultimately allowing the execution of unauthorized code.

How can an attacker trigger this vulnerability?

An attacker exploits this by interacting directly with the theme’s font upload mechanism, which lacks mandatory security checks like nonces or user capability verification. The bug is triggered when a file is sent to the vulnerable upload endpoint. It is not triggered by simply visiting the site or viewing pages; the attacker must specifically send a file request to the theme's upload function to bypass intended restrictions.

Why is this a risk for internet-facing sites?

According to Halo Surface Signal, this theme manages functionality commonly exposed to the public internet, such as file upload features. Because the vulnerability does not require authentication, an internet-facing WordPress instance running an older version of Zella effectively provides a direct path for remote actors to upload and run malicious code without needing valid administrative credentials.

Do I need to update my WordPress theme?

Yes. If you manage a site running the Zella Theme, your first step is to confirm the current version. Versions before 2.6.3 contain the flaw. You should identify all installations of this theme, determine if they are reachable from the internet, and prioritize applying the vendor's update. If an update cannot be applied immediately, consider disabling the vulnerable theme functionality or restricting access to the site.

References