Impact
The vulnerability is a PHP Object Injection flaw in the Entrepreneur – Booking for Small Businesses WordPress theme. Deserialization of untrusted data allows an attacker to insert malicious serialized objects, which the theme will unserialize. This flaw can lead to remote code execution and therefore compromises confidentiality, integrity and availability of the affected site.
Affected Systems
The product affected is the WordPress theme Entrepreneur – Booking for Small Businesses from Pixel Makers Creative are vulnerable. Any WordPress installation that uses these theme versions and processes user input that reaches the deserialization logic is at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1%, showing a very low exploitation probability, but not zero. The theme is not listed in the CISA KEV catalog. Exploitation would likely occur remotely via the web interface that accepts serialized data for the theme, and an attacker who can influence input fields or inject payloads could achieve remote code execution.
OpenCVE Enrichment