Impact
The vulnerability is a deserialization of untrusted data flaw that permits PHP object injection within the AncoraThemes Umberto theme. The weakness, identified as CWE-502, can allow an attacker to execute arbitrary code on the WordPress server, compromising confidentiality, integrity, and availability. This flaw arises when the theme unconditionally unserializes data that could be controlled by an external user.
Affected Systems
The affected product is the Umberto theme for WordPress, with every release from its initial version through and including 1.2.8 susceptible to this issue. Any WordPress site running this theme in those versions is potentially vulnerable; the problem remains if later versions revert or reintroduce unsafe practices.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity, while the EPSS score of under 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can reach the vulnerable code path remotely via crafted HTTP requests that deliver malicious serialized payloads; therefore the likely attack vector is remote and does not require privileged access. If exploited successfully, an attacker could gain full control over the affected WordPress server.
OpenCVE Enrichment
EUVD