Impact
The Goldish WordPress theme contains a deserialization vulnerability that allows untrusted data to be processed as PHP objects, enabling Object Injection. This weakness, identified as CWE-502, can be abused to execute arbitrary code, compromising the integrity and confidentiality of the affected website.
Affected Systems
All installations of the Goldish theme produced by park_of_ideas that are at a version older than 3.47 are affected. Versions 3.47 and newer contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog, but the potential impact is high. Based on the description, the likely attack vector involves submitting crafted serialized data through an HTTP request processed by the theme, which could allow a remote attacker to inject malicious objects without needing prior authentication. Publicly accessible WordPress sites running an affected version are therefore at risk of remote code execution.
OpenCVE Enrichment