Impact
The vulnerability is a Deserialization of Untrusted Data flaw that allows PHP Object Injection in the AncoraThemes BugsPatrol theme. When an attacker supplies crafted serialized data, the theme may instantiate unintended objects or alter object properties, potentially leading to arbitrary code execution. This weakness is classified as CWE-502.
Affected Systems
The affected product is the AncoraThemes BugsPatrol WordPress theme, versions 1.5.0 and earlier. The vulnerability exists across all releases up to and including version 1.5.0 and continues through unspecified earlier releases.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker sending crafted serialized input to the theme, possibly via a public web request that the theme processes. Because object injection can enable arbitrary code execution, the risk to affected sites is high. The limited exploit availability does not negate the need for remediation.
OpenCVE Enrichment