Unrestricted File Upload Vulnerability in WebsiteBaker CMS by WebsiteBaker
CVE-2026-61524

8.6HIGH

Key Information:

Vendor
CVE Published:
3 August 2026

What is CVE-2026-61524?

WebsiteBaker CMS prior to version 2.13.10 is affected by an unrestricted file upload vulnerability found in the module installation feature. This flaw permits authenticated administrators to upload a specially crafted ZIP archive that includes a PHP webshell along with a valid info.php metadata file. When exploited, the malicious archive is extracted to a web-accessible modules/ subdirectory, which enables any unauthenticated user to execute the webshell via direct HTTP requests, leading to potential remote code execution.

Affected Version(s)

WebsiteBaker CMS 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Benjamin Agyapong Asare
.