CVE-2024-58349: Wp Travel Kit Travelscape

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.

Affected products

Published 2026-06-08. Last modified 2026-07-23.