Impact
AncoraThemes Mr. Murphy is vulnerable to deserialization of untrusted data, allowing PHP object injection (CWE‑502). An attacker who can supply crafted serialized input can instantiate arbitrary PHP objects and execute malicious code on the target system. This flaw can compromise confidentiality, integrity, and availability, effectively enabling full remote code execution.
Affected Systems
WordPress installations that use the AncoraThemes Mr. Murphy theme, version 1.2.12.1 or earlier, are affected. The exact initial release is unspecified, so any deployment of the theme before version 1.2.12.1 is at risk.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating a high severity. Despite an EPSS score of less than 1 %, meaning current exploitation activity is low, the possibility of future attacks remains. The vulnerability is not listed in CISA’s KEV catalog. An attacker can likely exploit the flaw remotely by sending specially crafted HTTP requests that trigger the theme’s deserialization routines.
OpenCVE Enrichment
EUVD