Impact
The Visual Art | Gallery WordPress Theme includes a deserialization vulnerability that allows attackers to perform object injection by supplying untrusted data. This flaw can enable an attacker to execute arbitrary code on the server, compromise confidentiality, and modify data or disrupt services. The weakness is categorized as CWE‑502.
Affected Systems
Affected products are the WordPress theme Visual Art | Gallery WordPress Theme from designthemes. All releases from the initial version up to and including 2.4 are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1 %, suggesting a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker injects a crafted payload into a serialized field, such as a theme option or form input, which is later unserialized without validation. If successful, the attacker can execute arbitrary code on the host.
OpenCVE Enrichment
EUVD