Impact
The Medicare theme from BoldThemes contains a deserialization flaw that permits PHP object injection when it processes untrusted input. This weakness is identified as CWE-502 and can allow an attacker to execute arbitrary code on a vulnerable WordPress site. The vulnerability affects all releases of the Medicare theme up to and including version 2.1.0.
Affected Systems
WordPress installations that employ the BoldThemes Medicare theme version 2.1.0 or earlier are exposed. This includes any site that has not upgraded beyond the specified threshold.
Risk and Exploitability
The CVSS score of 9.8 signifies critical severity, and the EPSS score of less than 1% indicates a very low current exploitation likelihood. The issue is not listed in the CISA KEV catalog. The likely attack vector is the delivery of crafted serialized data to the theme, typically through specially constructed HTTP requests or user inputs processed by the theme. If an attacker succeeds in injecting a malicious object, they can gain remote code execution privileges on the affected WordPress installation.
OpenCVE Enrichment
EUVD