Impact
Deserialization of untrusted data in the DesignThemes Finance Consultant WordPress theme allows an attacker to inject arbitrary PHP object references. This object injection can lead to remote code execution, enabling the attacker to run unintended code, modify files, or acquire sensitive data. The vulnerability is based on CWE-502, a flaw in input handling that permits malicious client‑side payloads to be deserialized without validation.
Affected Systems
The problem is present in all releases of the DesignThemes Finance Consultant theme up to and including version 2.8. Any WordPress site that has not upgraded beyond 2.8 remains vulnerable as long as the theme remains active.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity issue, while the EPSS of less than 1 % suggests an unlikely current exploitation probability. Because the flaw surrounds PHP object deserialization, the most likely delivery methods involve sending crafted serialized payloads through form inputs or API endpoints that the theme processes. No known public exploits exist, and the vulnerability is not listed in the CISA KEV catalog, implying that active exploitation has not been documented.
OpenCVE Enrichment
EUVD