Description
Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Published: 2025-11-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Togo theme for WordPress contains a PHP Object Injection flaw caused by deserializing data that can be supplied by an attacker. Based on the description, it is inferred that the flaw stems from improper handling of serialized data supplied by users. The vulnerability, classified as CWE‑502, allows an attacker to craft malicious serialized objects that, when processed by the theme, can lead to arbitrary code execution within the server’s PHP context A successful exploitation would compromise the confidentiality, integrity, and availability of the entire website.

Affected Systems

The flaw exists in the Togo theme released by uxper for WordPress and applies to all versions before 1.0.4. Sites running any pre‑1.0.4 release of the theme are susceptible, regardless of the WordPress core version, and the issue is confined to the theme’s PHP code.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as High severity, while the EPSS score of less than 1% indicates a low probability of current exploitation. It is not yet listed in CISA’s KEV catalog, suggesting no active widespread attacks have been reported. Attackers would need to deliver crafted serialized input to the theme’s processing logic. The likely attack vector is the delivery of malicious serialized data through publicly accessible theme files or custom URLs, as inferred from the description. Because the flaw relies on untrusted data processing, a successful exploit can execute arbitrary code and compromise the entire web server.

Generated by OpenCVE AI on April 29, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Togo theme to version 1.0.4 or newer, which removes the deserialization issue.
  • If immediate upgrade is not possible, temporarily deactivate or remove the theme until a patched version is available to eliminate the attack surface.
  • Scan the theme’s PHP files for any use of unserialize() or other deserialization functions and replace them with safe parsing mechanisms or remove any processing of user‑supplied data; consider disabling custom theme code that may accept external serialization inputs.

Generated by OpenCVE AI on April 29, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Title WordPress Togo theme < 1.0.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:49:49.967Z

Reserved: 2025-10-07T15:34:26.390Z

Link: CVE-2025-62035

cve-icon Vulnrichment

Updated: 2025-11-06T18:17:25.290Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:09.780

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:15:15Z

Weaknesses