Impact
The Booklovers Theme for WordPress contains a deserialization of untrusted data vulnerability that permits PHP Object Injection. This flaw allows an attacker to inject malicious objects during the unserialize process, potentially leading to remote code execution on the affected site. The weakness aligns with CWE‑502, illustrating that untrusted input is being deserialized without adequate validation.
Affected Systems
ThemeREX Group’s Booklovers WordPress theme versions up to and including 2.13.0 are impacted. All installations of the theme in these version ranges are susceptible until the theme is upgraded past 2.13.0.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical, signifying a high likelihood of successful exploitation and severe impact. Because the EPSS score is not available, exact exploitation probability cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely exploit it through crafted requests that reach the theme’s deserialization code, enabling remote code execution on the WordPress site.
OpenCVE Enrichment