Impact
The vulnerability is a PHP serialization flaw that allows an attacker to inject arbitrary PHP objects into the Traveler theme. This can lead to remote code execution, compromising site confidentiality, integrity, or availability.
Affected Systems
The flaw affects the shinetheme Traveler WordPress theme in all versions earlier than 3.2.8.1. WordPress sites that have the Traveler theme installed and have not upgraded beyond that version are vulnerable.
Risk and Exploitability
The CVSS score is not listed here, but the EPSS indicates a low probability of exploitation (<1%). The vulnerability has not been identified in the CISA KEV catalog. Likely attack vector is web-based input that triggers deserialization, such as form submissions or URLs. Because object injection can execute code, the risk to affected sites is significant if an attacker can supply malicious payloads.
OpenCVE Enrichment