Impact
The vulnerability lies in the WordPress Car Zone theme's handling of serialized data. Deserialization of untrusted data allows an attacker to inject malicious objects, potentially resulting in remote code execution or privilege escalation. This flaw is identified as a CWE‑502 deserialization weakness.
Affected Systems
Affected installations are those using AivahThemes Car Zone theme version 3.7 and older. All releases from the earliest available version through 3.7 are susceptible. Administrators should verify the theme version and update or replace it.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity impact. The EPSS score of less than 1% suggests a low likelihood of current exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector involves submitting crafted serialized payloads to the theme, which could be achieved via HTTP requests or administrative interfaces. Due to the high potential consequence, monitoring for anomalous requests and applying mitigations is recommended.
OpenCVE Enrichment