Impact
The vulnerability is a deserialization of untrusted data that permits PHP object injection in the FuelThemes North WordPress theme. An attacker who can supply arbitrary serialized data to the application could cause the application to instantiate malicious objects, potentially leading to remote code execution, defacement, or data exfiltration. The weakness is identified as CWE‑502.
Affected Systems
This flaw affects the North theme from its earliest releases up through version 5.7.5. The theme is distributed by FuelThemes and is available to all WordPress sites that have the North theme installed. Versions 5.7.6 and later have the deserialization issue resolved.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity with the possibility of exploit outside of owned networks. The EPSS score is below 1%, pointing to a low probability of active exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely leverage remote HTTP requests containing crafted serialized payloads; no privileged access or local privileges are required. Because the attack vector is inferred to be remote and user‑controlled, sites exposed to the internet are at risk.
OpenCVE Enrichment