Impact
An unauthenticated PHP Object Injection flaw allows an attacker to manipulate serialized data that the Reisen theme processes. This vulnerability can lead to arbitrary code execution on the web server, enabling full compromise of the site, theft of data, or further propagation of malware. The weakness is identified as CWE-502.
Affected Systems
ThemeREX Reisen theme versions 1.4.1 and earlier are vulnerable. The issue exists in all releases of Reisen up to and including 1.4.1.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity. EPSS data is not available, but the absence of mitigation means potential exploitation is high. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a remote web request that passes crafted serialized input to the theme, which is then unserialized without proper validation.
OpenCVE Enrichment