Goza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
2025-09-08 19:58
GR0VStrategic Overview
StatusPatched in 3.2.3
Affected ThemeGoza - Nonprofit Charity WordPress Theme
Affected Version
<= 3.2.2CVSS9.8Critical
CVE
CVE-2025-10690Vulnerability Overview
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the 'beplus_import_pack_install_plugin' function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.
Technical Analysis
REMEDIATION: Update to version 3.2.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C