Critical severity9.8NVD Advisory· Published Jun 8, 2026· Updated Jun 8, 2026
CVE-2024-58349
CVE-2024-58349
Description
WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2=1.0.3+ 1 more
- (no CPE)range: =1.0.3
- (no CPE)range: <=1.0.3
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.