VYPR
Critical severity9.9NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-40750

CVE-2026-40750

Description

Kids Online Store theme ≤0.8.9 allows unauthenticated arbitrary file upload, enabling web shell deployment and full site compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Kids Online Store theme ≤0.8.9 allows unauthenticated arbitrary file upload, enabling web shell deployment and full site compromise.

Vulnerability

Kids Online Store, a WordPress theme by themagnifico52, contains an Unrestricted Upload of File with Dangerous Type vulnerability in versions from n/a through 0.8.9. The theme fails to properly validate file types during upload, allowing an attacker to upload arbitrary files including executable scripts (web shells) to the web server [1].

Exploitation

An unauthenticated attacker with network access to a WordPress site running the vulnerable theme can upload a malicious file (e.g., a PHP web shell) through the theme's file upload functionality. No prior authentication or special privileges are required. The attacker simply submits a crafted file upload request, bypassing content-type or extension checks due to the lack of proper validation [1].

Impact

Successful exploitation allows the attacker to upload and execute a web shell on the server, granting them remote code execution with the web server's privileges. This can lead to full site compromise, including data theft, backdoor installation, and further propagation within the hosting environment. The vulnerability is rated Critical with a CVSS v3 score of 9.9 [1].

Mitigation

The vendor has released a fix; users must update the Kids Online Store theme to a version higher than 0.8.9 immediately. If unable to update, contact your hosting provider or web developer for assistance. The vulnerability is listed as highly likely to be exploited in mass campaigns [1].

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.