Impact
A deserialization flaw in the LoftOcean CozyStay WordPress theme allows an attacker to inject arbitrary PHP objects. The vulnerability maps to CWE-502 and can give an attacker full control over the execution flow on a compromised site. If exploited, confidentiality, integrity, and availability of the web server and WordPress installation could be undermined, allowing arbitrary code execution or data exfiltration.
Affected Systems
All installations of the LoftOcean CozyStay theme with a version prior to 1.7.1 are vulnerable when deployed on WordPress sites. The issue applies to every user who has not updated the theme to the fixed release.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity. The EPSS score indicates a very low current exploitation probability (< 1%), and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential impact is high and attackers could exploit the flaw remotely by delivering a crafted serialized payload to a WordPress site running the affected theme. The attack vector is inferred to be remote, given the nature of PHP object injection in web applications.
OpenCVE Enrichment
EUVD