Impact
Deserialization of untrusted data in the Apicona theme allows the injection of arbitrary PHP objects. The object injection can lead to erroneous code execution if the deserialized data is processed insecurely. Based on the description, it is inferred that the injected objects might enable unauthorized code execution within the WordPress site.
Affected Systems
The vulnerability affects WordPress installations using the Apicona theme from TheMount, from the initial release through version 24.1.0. Any site running these theme versions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. The likely attack vector involves submitting crafted data that the theme deserializes—such as via a URL parameter or form input—and, based on the description, it is inferred that exploitation could grant elevated privileges or allow arbitrary PHP code execution.
OpenCVE Enrichment