Impact
The vulnerability is a PHP Object Injection flaw caused by deserialization of untrusted data. If an attacker can supply crafted data to the WordPress VEDA theme, they may instantiate arbitrary objects, potentially leading to execution of malicious code or other severe consequences on the affected system.
Affected Systems
DesignThemes VEDA WordPress theme versions up to and including 4.2 are affected. Users deploying these versions on their sites are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity. The EPSS score is below 1% indicating a very low probability of exploitation in current open‑source deployments, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for remote code execution makes immediate remediation critical once a version higher than 4.2 becomes available.
OpenCVE Enrichment