Impact
Unauthenticated PHP Object Injection vulnerability exists in WordPress CleanSkin theme versions up to 1.5.0. The flaw allows an attacker to instantiate arbitrary PHP objects and inject malicious serialized data, potentially leading to remote code execution, data tampering, and service denial.
Affected Systems
The affected product is the AncoraThemes CleanSkin WordPress theme. All installations running CleanSkin version 1.5.0 or earlier are vulnerable.
Risk and Exploitability
The high CVSS score of 9.8 highlights the severe impact of this vulnerability. Attackers can exploit the flaw remotely without authentication by sending crafted requests to the web application, making exploitation highly feasible. Since EPSS is not listed and the vulnerability is not in CISA's KEV catalog, the exact exploitation frequency is unknown, but the high severity suggests it is a prime target for attackers seeking RCE.
OpenCVE Enrichment