Arbitrary File Upload Vulnerability in PX-lab Zombify Product
CVE-2026-94503

10CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-94503?

The PX-lab Zombify application is susceptible to an arbitrary file upload vulnerability that allows attackers to upload web shells to the server. This can result in unauthorized access and control over the affected server. Users of Zombify, particularly those running versions from n/a up to 1.7.7, are encouraged to apply security updates promptly to mitigate the risk of exploitation.

Affected Version(s)

Zombify 0 <= 1.7.7

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.