Impact
CVE-2026-65571 exposes an unauthenticated PHP Object Injection flaw in the 69 Clothing WordPress theme up to version 1.2.11.1. The vulnerability permits an attacker to instantiate arbitrary PHP objects without any authentication, potentially modifying application behavior or executing malicious code. This weakness is categorized as CWE‑502 and represents a critical security gap in the theme's handling of serialized data.
Affected Systems
WordPress sites using the 69 Clothing theme from Axiomthemes, including all releases dated 1.2.11.1 and earlier. The flaw exists in the core theme code that processes user-supplied data and does not require any special credentials to be triggered.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity, and the lack of an EPSS score indicates the exploitation probability is not quantified yet, but the vulnerability is unauthenticated and thus widely exploitable. Because the flaw is not listed in the CISA KEV catalog, it may still be actively exploited by attackers using the theme's default configuration. The principal attack vector is through web input that the theme accepts, such as plugin or form data, and the impact remains undefined until a full exploit chain is demonstrated.
OpenCVE Enrichment