Input validation vulnerability in curvo *

The Curvo Theme for WordPress is vulnerable to a security flaw that allows malicious actors to upload dangerous files to sites that use the theme. This vulnerability is present in all known versions of the theme and involves the upload-handler.php file which does not validate the type of files being uploaded. If a malicious actor is able to upload a file, it could potentially give them access to the server and allow them to execute remote code.

Detected in:

curvo fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.