Impact
BoldThemes DentiCare theme contains a deserialization flaw that allows an attacker to inject arbitrary PHP objects when the theme processes user‑supplied data. If an attacker can control the serialized payload, they can execute unintended code on the server, leading to full compromise of the WordPress site. The flaw is based on CWE‑502, which involves unsafe deserialization of untrusted data.
Affected Systems
WordPress sites running the DentiCare theme version earlier than 1.4.3 are affected. The issue applies to all releases from the initial version up to just before 1.4.3, including any custom WordPress installations that have installed the theme through BoldThemes or a marketplace.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical vulnerability with high impact. However, the EPSS score of less than 1 % suggests that the likelihood of real‑world exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to find an entry point that accepts serialized data from an untrusted source, such as form inputs or URL query parameters, to exploit the flaw. Successful exploitation could result in remote code execution and full system compromise.
OpenCVE Enrichment