CVE-2025-68553Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through < 2.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 103-0503-0603-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-68553 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/… https://www.cve.org/CVERecord?id=CVE-2025-68553

    Post summary

    A new unrestricted file upload vulnerability (CVE‑2025‑68553) in the Lendiz theme has been disclosed, enabling attackers to upload web shells. No PoC, exploit, patch, or active exploitation details were provided.

    00000191
    56.6K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: WordPress themes and OpenClaw stack (CVSS 9.8-9.9) Affected: zozothemes Lendiz; zozothemes Nutrie; Nginx UI; OpenClaw Internet-facing exposure dominates, led by WordPress themes and OpenClaw components; fixes and mitigations below. • CVE-2025-68553 (CVSS 9.9) Lendiz WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server. • CVE-2025-68555 (CVSS 9.9) Nutrie WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server. • CVE-2026-27944 (CVSS 9.8) Nginx UI prior to 2.3.3 has an unauthenticated /api/backup endpoint that discloses the encryption keys required to decrypt backups via the X-Backup-Security header. • CVE-2026-28391 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, enabling remote command execution. • CVE-2026-28470 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 contain an exec approvals allowlist bypass that enables attackers to execute arbitrary commands by injecting command substitution syntax. 🛠️ Action • Patch/upgrade to the fixed versions called out by vendors and advisories for Lendiz, Nutrie, Nginx UI, and OpenClaw. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply stated mitigations and reduce exposure (disable vulnerable features/modules, restrict access). • Add detections for exploitation patterns (web shells, file-write paths, auth anomalies, command substitutions). • Hunt for indicators around the affected services during the disclosure window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces several high‑CVSS CVEs affecting WordPress themes and OpenClaw components, details their technical characteristics, and recommends vendor patches and mitigations.

    00000130
    85 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-68553 - Critical Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through &amp;lt; 2.0.1. https://www.thehackerwire.com/vulnerability/CVE-2025-68553/ https://t.co/5vmzR3s8mq

    Post summary

    CVE‑2025‑68553 is a critical untrusted file upload flaw in Zozothemes Lendiz (v2.0.1 and below) that permits uploading a web shell. No PoC, exploit code, active exploitation, or patch information is included in the text.

    0000082
    124 followersView on X

Explore more