


Perceptive Security
SOC/SIEM Consultancy

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: f…
Published:
4 maart 2026 om 23:00:00
Alert date:
5 maart 2026 om 20:09:02
Source:
nvd.nist.gov
Web Technologies
A critical unrestricted file upload vulnerability exists in the zozothemes Lendiz WordPress theme that allows attackers to upload web shells to web servers. The vulnerability affects all versions of Lendiz prior to version 2.0.1. This type of vulnerability enables remote code execution through malicious file uploads, potentially leading to complete server compromise. The issue has been assigned CVE-2025-68553 and represents a significant security risk for WordPress sites using the affected theme versions.
Technical details
Mitigation steps:
Affected products:
zozothemes Lendiz WordPress theme
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-68553
https://patchstack.com/database/Wordpress/Theme/lendiz/vulnerability/wordpress-lendiz-theme-2-0-1-arbitrary-file-upload-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
