Impact
Deserialization of untrusted data in the BoldThemes Travelicious theme allows an attacker to inject malicious PHP objects. This object injection can lead to arbitrary PHP code execution, giving the attacker full control over the affected web server. The flaw arises because the theme processes user‑supplied input without proper validation.
Affected Systems
The vulnerability affects all installations of the WordPress Travelicious theme with a version earlier than 1.6.7. Vendors and administrators using BoldThemes Travelicious need to verify their theme version; any version that predates 1.6.7 is potentially compromised.
Risk and Exploitability
With a CVSS score of 9.8, the risk is critical. The EPSS score of less than 1% indicates that, as of now, the likelihood of real‑world exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based input path that deserializes data, meaning an attacker could remotely trigger the flaw on a publicly accessible site. While the lack of a known exploit keeps the risk theoretical, the severity warrants urgent patching.
OpenCVE Enrichment