Description
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
Published: 2026-07-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A deserialization flaw in the axiomthemes 777 triple-seven WordPress theme up to version 1.13.0 allows an attacker to inject a crafted object into PHP’s unserialize routine, classified as CWE-502. Exploiting this can give the attacker arbitrary code execution on the affected WordPress site by delivering unsanitized serialized data that the theme processes without validation.

Affected Systems

The 777 theme sold by axiomthemes is affected when installed in WordPress. The vulnerability exists in all releases up to and including version 1.13.0 and does not affect any other product or vendor.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical level of risk, while the EPSS score of less than 1% suggests that exploitation in the wild is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote injection of serialized data via a crafted request to the theme, such as a form submission or a query parameter that the theme processes without filtering. Successful exploitation would allow the attacker to execute arbitrary code on the compromised WordPress installation.

Generated by OpenCVE AI on August 1, 2026 at 10:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Temporarily deactivate or uninstall the 777 theme to eliminate the deserialization vector.
  • Upgrade the theme to a version newer than 1.13.0 once the vendor releases a fix; if no newer version exists, consider switching to an alternative theme.
  • Monitor the vendor’s release channel and apply any future updates as soon as they become available.

Generated by OpenCVE AI on August 1, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Axiomthemes
Axiomthemes 777
Wordpress
Wordpress wordpress
Vendors & Products Axiomthemes
Axiomthemes 777
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
Title WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Axiomthemes 777
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:53:01.682Z

Reserved: 2026-06-25T08:04:29.578Z

Link: CVE-2026-57738

cve-icon Vulnrichment

Updated: 2026-07-13T13:52:58.672Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data