Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through < 2.0.1.
CVE-2025-68555 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/… https://www.cve.org/CVERecord?id=CVE-2025-68555
Post summary
The text discloses an unrestricted file upload vulnerability in the Nutrie theme that could allow attackers to upload a web shell, potentially enabling remote code execution.
🚨 Critical CVEs Today: WordPress themes and OpenClaw stack (CVSS 9.8-9.9)
Affected: zozothemes Lendiz; zozothemes Nutrie; Nginx UI; OpenClaw
Internet-facing exposure dominates, led by WordPress themes and OpenClaw components; fixes and mitigations below.
• CVE-2025-68553 (CVSS 9.9) Lendiz WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server.
• CVE-2025-68555 (CVSS 9.9) Nutrie WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server.
• CVE-2026-27944 (CVSS 9.8) Nginx UI prior to 2.3.3 has an unauthenticated /api/backup endpoint that discloses the encryption keys required to decrypt backups via the X-Backup-Security header.
• CVE-2026-28391 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, enabling remote command execution.
• CVE-2026-28470 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 contain an exec approvals allowlist bypass that enables attackers to execute arbitrary commands by injecting command substitution syntax.
🛠️ Action
• Patch/upgrade to the fixed versions called out by vendors and advisories for Lendiz, Nutrie, Nginx UI, and OpenClaw.
• Prioritize internet-facing instances and edge appliances first.
• If no fix yet, apply stated mitigations and reduce exposure (disable vulnerable features/modules, restrict access).
• Add detections for exploitation patterns (web shells, file-write paths, auth anomalies, command substitutions).
• Hunt for indicators around the affected services during the disclosure window (logs, EDR, WAF).
• Validate remediation (version checks, config verification) and monitor for reversion
Post summary
Several high‑CVSS vulnerabilities in WordPress themes and OpenClaw are disclosed, with clear patch and mitigation guidance but no evidence of active exploitation or PoC details.
🔴 CVE-2025-68555 - Critical
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through &lt; 2.0.1.
https://www.thehackerwire.com/vulnerability/CVE-2025-68555/ https://t.co/Ts8mi1IiMc
Post summary
The post announces CVE-2025-68555, detailing an unrestricted file upload flaw that permits uploading a web shell to Nutrie versions prior to 2.0.1.