A vulnerability has been reported in the Kiddo theme for WordPress, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to the /wp-content/themes/kiddo/app/assets/js/uploadify/uploadify.php script allowing the upload of files with arbitrary extensions to a folder inside the webroot. This can be exploited to execute arbitrary PHP code by uploading a malicious PHP script.