CVE-2024-58349 - CVE House
Back to Database
Status published Critical CVE-2024-58349

WordPress Theme Travelscape 1.0.3 Arbitrary File Upload

Vulnerability Description

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58349

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Milad Karimi (Ex3ptionaL)

Affected Vendor

WP Travel Kit

View all reports →

Affected Software

Travelscape
Vulnerable Versions:
1.0.3

Timeline

Official Publish: June 8th, 2026
Last Modified: June 8th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)