top of page
perceptive_background_267k.jpg

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 14:04:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

CVE-2026-27419 describes an Arbitrary File Upload vulnerability affecting the Zegen WordPress theme in versions 1.1.9 and below. The flaw allows subscriber-level authenticated users to upload arbitrary files to the server, which can potentially lead to remote code execution. This type of vulnerability is particularly dangerous as it can enable attackers to plant malicious scripts or backdoors on the affected WordPress site. The vulnerability has been documented by both the NVD and Patchstack. A patch or updated version beyond 1.1.9 is expected to remediate the issue. WordPress theme vulnerabilities of this nature represent a significant risk to site owners who have not applied security updates.

Technical details

Mitigation steps:

Affected products:

Zegen WordPress Theme <= 1.1.9

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page