Impact
The vulnerability originates from insecure deserialization of untrusted data in the VictorThemes Seil theme, allowing attackers to perform object injection. This weakness is classified as CWE-502 and can enable arbitrary code execution, compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
All installations of the VictorThemes Seil theme version 1.7.1 or earlier are affected. The flaw exists from the theme’s inception up to and including 1.7.1; no newer version is known to be affected.
Risk and Exploitability
The EPSS score of less than 1% suggests limited exploitation activity to date, and the vulnerability is not listed in CISA KEV. However, the high CVSS score of 9.8 indicates severe potential impact if exploited. Attackers would need to supply malicious serialized data to the theme, which is likely achievable remotely via crafted HTTP requests or uploaded content, giving them potential to execute code on the server. Vigilance and timely patching are therefore essential.
OpenCVE Enrichment