


Perceptive Security
SOC/SIEM Consultancy

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: f…
Published:
4 March 2026 at 23:00:00
Alert date:
5 March 2026 at 20:09:02
Source:
nvd.nist.gov
Web Technologies
Critical vulnerability in zozothemes Nutrie WordPress theme allows unrestricted file uploads with dangerous file types. Attackers can upload web shells to web servers, enabling remote code execution. Affects Nutrie theme versions prior to 2.0.1. This vulnerability enables attackers to gain unauthorized access to web servers through malicious file uploads. The issue has been identified and patched in version 2.0.1 of the theme.
Technical details
Mitigation steps:
Affected products:
Nutrie WordPress Theme
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-68555
https://patchstack.com/database/Wordpress/Theme/nutrie/vulnerability/wordpress-nutrie-theme-2-0-1-arbitrary-file-upload-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
