Impact
The vulnerability is a PHP Object Injection flaw caused by the deserialization of untrusted data within the WordPress Equestrian Centre theme. An attacker can craft malicious serialized input that, when deserialized by the theme, may instantiate arbitrary PHP objects and execute code, leading to full control over the affected web server.
Affected Systems
This issue affects all installations of the ThemeREX Equestrian Centre theme from its earliest version up through 1.5 inclusive. No specific patched release version is listed in the advisory, but the vendor recommends upgrading beyond 1.5 to eliminate the vulnerability.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% points to a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, web‑based, likely requiring no authentication because the deserialization process occurs on user‑supplied data. If exploited, the impact is complete compromise of the web application and possibly the underlying server, providing attackers with system‑wide access.
OpenCVE Enrichment