Impact
The ColorFolio theme contains a flaw that deserializes untrusted data, allowing an attacker to inject serialized objects. This opens the possibility for arbitrary code execution if the attacker can supply a crafted payload, which could compromise the WordPress site’s confidentiality, integrity, and availability. The impact is limited to installations that use the vulnerable theme, but the consequences could affect the entire site.
Affected Systems
The affected product is BuddhaThemes ColorFolio – Freelance Designer WordPress Theme. All releases from the earliest available version through 1.3 inclusive are vulnerable. No additional sub‑products or variants are listed.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. EPSS data shows a very low exploitation probability (less than 1%), suggesting that the vulnerability is not currently widely exploited. The theme is delivered via WordPress, so a remote attack vector is likely, inferred from the public nature of WordPress sites and potential deserialization points such as widgets or shortcodes. The vulnerability is not listed in the CISA KEV catalog. Overall, the risk remains high due to the severity score and the potential for critical compromise if the flaw is effectively exploited.
OpenCVE Enrichment