CVE-2026-32482: WordPress Ona theme < 1.24 - Arbitrary File Upload vulnerability
Published Mar 25, 2026
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.
Affected Software
1 affected component
DeoThemes Ona (WordPress theme)<1.24
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-32482?
CVE-2026-32482 is classified as a high severity vulnerability due to the potential for arbitrary file uploads that may lead to web shell access.
2
How do I fix CVE-2026-32482?
To fix CVE-2026-32482, update the Ona theme to version 1.24 or higher to mitigate the arbitrary file upload vulnerability.
3
What types of files can be uploaded in CVE-2026-32482?
CVE-2026-32482 allows the upload of dangerous file types, potentially including web shells.
4
Which versions of the Ona theme are affected by CVE-2026-32482?
CVE-2026-32482 affects all versions of the Ona theme prior to 1.24.
5
What are the potential impacts of CVE-2026-32482?
The potential impacts of CVE-2026-32482 include unauthorized access to the web server and the ability to execute malicious scripts.