CVE-2023-54352: Wp Travel Kit Travelscape
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and upload additional files for persistent access.
Affected products
- Wp Travel Kit Travelscape: version 1.0.3 only
Published 2026-06-08. Last modified 2026-07-23.