


Perceptive Security
SOC/SIEM Consultancy

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 14:04:37
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-27419 describes an Arbitrary File Upload vulnerability affecting the Zegen WordPress theme in versions 1.1.9 and below. The flaw allows subscriber-level authenticated users to upload arbitrary files to the server, which can potentially lead to remote code execution. This type of vulnerability is particularly dangerous as it can enable attackers to plant malicious scripts or backdoors on the affected WordPress site. The vulnerability has been documented by both the NVD and Patchstack. A patch or updated version beyond 1.1.9 is expected to remediate the issue. WordPress theme vulnerabilities of this nature represent a significant risk to site owners who have not applied security updates.
Technical details
Mitigation steps:
Affected products:
Zegen WordPress Theme <= 1.1.9
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27419
https://patchstack.com/database/wordpress/theme/zegen/vulnerability/wordpress-zegen-theme-1-1-9-arbitrary-file-upload-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
