Impact
The Gutentype theme processes serialized data supplied by users without proper validation, allowing attackers to inject malicious PHP objects. When the application deserializes this data, the injected objects can execute arbitrary methods, potentially giving the attacker full control over the site. This flaw may enable attackers to alter site content, inject scripts, or compromise the server’s filesystem if the code execution path is triggered.
Affected Systems
WordPress users running the ThemeREX Group Gutentype theme version 2.1.12 or earlier are affected. The vulnerability is present from the earliest released version up to and including 2.1.12. All installations that have not applied a newer version are at risk.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating a severe vulnerability. EPSS data is not available, making it unclear how frequently exploit attempts occur, but the lack of a KEV listing does not diminish the potential impact. Based on the description, the likely attack vector is remote via crafted HTTP requests that carry the malicious serialized payload. Successful exploitation would enable the attacker to execute server‑side code with whatever permissions the web application possesses.
OpenCVE Enrichment