CVE-2026-27043: WordPress Photography theme < 7.7.6 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a before 7.7.6.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography photography allows Path Traversal.This issue affects Photography: from n/a through < 7.7.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27043?
CVE-2026-27043 is considered a high severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2026-27043?
To fix CVE-2026-27043, update the ThemeGoods Photography theme to a version later than 7.7.5.
What systems are affected by CVE-2026-27043?
CVE-2026-27043 affects ThemeGoods Photography versions from n/a up to and including 7.7.5.
What type of vulnerability is CVE-2026-27043?
CVE-2026-27043 is classified as an Arbitrary File Upload vulnerability, allowing for potentially malicious file uploads.
What is the potential impact of CVE-2026-27043?
The impact of CVE-2026-27043 can include unauthorized access and control over the affected web server through malicious file execution.