Impact
The vulnerability is a PHP Object Injection (CWE‑502) that arises from deserializing untrusted data in the Fish House theme. An attacker can supply crafted serialized payloads, enabling them to instantiate objects of arbitrary classes. This can bypass normal access controls, inject malicious code, or execute arbitrary statements, leading to full compromise of the site and allowing a remote attacker to modify files or upload malware.
Affected Systems
The affected product is the AncoraThemes Fish House WordPress theme version 1.2.7 and earlier. This includes all releases from the theme’s introduction through to 1.2.7. The vulnerability does not affect any other themes or core WordPress components.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity. Although the EPSS score of less than 1% indicates a low exploitation probability at present, and the vulnerability is not listed in the CISA KEV catalog, Object Injection can enable remote code execution with only a serialized payload injected via a public endpoint. Any site running a vulnerable theme is at substantial risk of full takeover, data loss, defacement, or further network intrusion.
OpenCVE Enrichment
EUVD