Impact
Axiom Themes Sweet Dessert theme contains a deserialization flaw that permits PHP object injection. The vulnerability allows an attacker to supply crafted data that causes the theme to instantiate malicious objects. If exploited, the attacker may gain remote code execution on the affected WordPress installation, compromising confidentiality, integrity, and availability of the entire site.
Affected Systems
The issue is present in Sweet Dessert versions from the initial release up to, but excluding, 1.1.13. Any WordPress site that has the Sweet Dessert theme installed and does not run a later version is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical, while the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers would likely exploit the flaw by submitting untrusted data that the theme processes, such as form submissions or embedded content, leading to object injection and potentially remote code execution.
OpenCVE Enrichment
EUVD