Input validation vulnerability in 8 themes by Orange themes

Various themes for WordPress that are branded as “Orange” are vulnerable to having malicious files uploaded to them without proper authentication. This is due to a security flaw in the ‘/functions/upload-handler.php’ file, which can be exploited to upload arbitrary files. If this exploit is successful, it could allow an attacker to execute code on the affected site’s server, which could lead to further malicious activity.

Detected in:

AgriTourismo fixed vulnerable versions: >= * <= *
Bordeaux Theme fixed vulnerable versions: >= * <= *
Bulteno Theme fixed vulnerable versions: >= * <= *
Oxygen Theme fixed vulnerable versions: >= * <= *
Radial Theme fixed vulnerable versions: >= * <= *
Rayoflight Theme fixed vulnerable versions: >= * <= *
Reganto Theme fixed vulnerable versions: >= * <= *
Rockstar Theme fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.