• Home
  • About Us
  • Authors
  • Submit News
  • Contact Us
  • Privacy Policy
  • Sitemap
The Hack Post
  • Hacking News
    • Cyber Crime
  • Cyber Security
  • Technology
    • Internet
  • Entertainment
    • Gaming
  • Business
  • Science / Health
No Result
View All Result
The Hack Post
No Result
View All Result

WordPress Theme “dance-studio” Vulnerable to Arbitrary Shell Upload

Afrasiab Khan by Afrasiab Khan
February 14, 2017
Wordpress Theme "dance-studio" Vulnerable to Arbitrary Shell Upload
Share on FacebookShare on Twitter

A vulnerability in the WordPress theme “dance-studio” has been discovered allowing attackers to upload malicious files like a shell, onto the targeted website. The exploit was posted to the exploit database, “0.day.today?” and has been authored by a security analyst going by the alias of xBADGIRL21. The exploit when used uploads a shell file onto the website through the “/wp-content/uploads/” directory path.

Screenshot of full exploit uploaded onto 0day.today? exploit database by xBADGIRL21
Screenshot of full exploit uploaded onto 0day.today? exploit database by xBADGIRL21

xBADGIRL21 also uploaded a YouTube video showing proof as to how the exploit can be used to breach WordPress websites who have the theme installed. The exploit runs a html script that grants permission to the hacker to upload any file they desire.

Video proof of concept (PoC) of the exploitation of the vulnerability uploaded to YouTube by author xBADGIRL21:

Code used to upload the shell onto the dance-studio themed WordPress website:

Screenshot of html code of the exploit
Screenshot of html code of the exploit

WordPress itself has nothing to do with the bugs found. It is solely an issue with the code the programmers of the theme have implemented. The theme creators and coders are not yet aware of the exploit as of yet since no patch has been made or deployed. The creators of the dance-studio theme have not addressed the critical vulnerability as of yet either.

Tags: WordpressWordpress Theme
Afrasiab Khan

Afrasiab Khan

A newbie writer at The Hack Post. Completely in love with technology. Writing has always been a passion of mine and so is hacking. Combine them together and you get me. A bit of experience in the fields of cyber security and looking to expand on that in the times to come. As a student of Engineering, being an author at The Hack Post helps me cope with the stress that comes with that.

Next Post
UK Police Website Hacked

UK Police Website Hacked by Turkish Hackers

Latest Articles

Smartphone displaying AI-generated voice assistant, symbolizing rising vishing cybersecurity threats
Cyber Security

The AI Clone in Your Pocket: Why ‘Vishing’ Is The Big New Threat

January 9, 2026
Image 1 of Mold Remediation Costs in Florida: The 2026 Guide for Homeowners
Business

Mold Remediation Costs in Florida: The 2026 Guide for Homeowners

January 9, 2026
Table tennis paddle and ball demonstrating spin technique for Shlomo Adelman spin shots overview
Entertainment

Shlomo Adelman: A Basic Overview of Spin Shots in Table Tennis

January 2, 2026
Adorable puppy wearing a red bow surrounded by Christmas gifts under a decorated holiday tree
Entertainment

A Gift for Life: Factors to Weigh When Giving a Pet this Christmas

December 26, 2025
Ai augmented
Business

AI-Augmented EB1A Pathway: How AI Improves EB1A Petitions

December 23, 2025
Lentor Gardens Residences modern condominium exterior in Singapore with lush landscaping
Business

Lentor Gardens Residences Condo: Redefining Modern Urban Living in Singapore

December 19, 2025
Server room with warning symbol, illustrating SMB disaster recovery and overlooked business risks
Cyber Security

Disaster Recovery: The Hidden Risk Most SMBs Ignore Until It’s Too Late

December 13, 2025
Image 1 of Through Hole PCB Assembly: A Complete Guide to a Trusted and Durable Manufacturing Method
Business

Through Hole PCB Assembly: A Complete Guide to a Trusted and Durable Manufacturing Method

December 11, 2025
JailCore digital dashboard monitoring correctional facility security and operations
Business

JailCore: Technology Supporting Safer Correctional Operations

December 9, 2025
Essential travel gadgets neatly arranged on a suitcase, ready for a modern traveler’s journey.
Featured

5 Must-Have Gadgets for Every Traveler

November 27, 2025
Dynamic camera movement illustrating audience perception concepts in film and media analysis
Entertainment

Andrew Laurendi: Camera Movement And Audience Perception Explained

November 20, 2025
Modern Narra Residences building showcasing advanced homebuying technology and smart features
Business

Narra Residences Revolutionizing Homebuying with Innovative Technology

November 17, 2025
  • Home
  • About Us
  • Authors
  • Submit News
  • Contact Us
  • Privacy Policy
  • Sitemap

The Hack Post © 2019

No Result
View All Result
  • Hacking News
    • Cyber Crime
  • Cyber Security
  • Technology
    • Internet
  • Entertainment
    • Gaming
  • Business
  • Science / Health

The Hack Post © 2019