A vulnerability was found in WebsiteBaker Org WebsiteBaker up to 2.13.9 and classified as problematic. The impacted element is an unknown function of the file info.php of the component Module Installation. Such manipulation leads to unrestricted upload.

This vulnerability is traded as CVE-2026-61524. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.