CVE-2025-26970: WordPress Ark Theme Core plugin < 1.71.0 - Unauthenticated Remote Code Execution (RCE) vulnerability
Published Mar 3, 2025
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Ark Theme Core ark-core allows Code Injection.This issue affects Ark Theme Core: from n/a through < 1.71.0.
Affected Software
2 affected components
WordPress Ark Theme Core<=1.70.0
Arktheme The Ark Wordpress<=1.70.0
Remediation
Information
Update to 1.71.0 or a higher version.
Event History
Mar 3, 2025
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 58279
Event
via MITRE·07:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-26970?
CVE-2025-26970 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-26970?
To fix CVE-2025-26970, upgrade the Ark Theme Core to version 1.70.1 or later.
3
What types of attacks can exploit CVE-2025-26970?
CVE-2025-26970 can be exploited through unauthenticated remote code execution, allowing attackers to execute arbitrary code.
4
Which versions of Ark Theme Core are affected by CVE-2025-26970?
CVE-2025-26970 affects all versions of Ark Theme Core up to and including 1.70.0.
5
Is there a workaround for CVE-2025-26970 if I cannot update immediately?
A workaround for CVE-2025-26970 includes disabling the Ark Theme Core plugin until an update can be applied.