Impact
An unauthenticated PHP Object Injection flaw is present in WordPress A.Williams theme versions 1.3.1 and earlier. The flaw allows an attacker to supply serialized objects that are deserialized without validation, giving the attacker the ability to execute arbitrary PHP code, modify data, or potentially compromise the entire site. The weakness is classified as CWE-502.
Affected Systems
WordPress sites that have the A.Williams theme (developed by Axiomthemes) installed and running version 1.3.1 or earlier are affected. Any site that has not upgraded past this version remains vulnerable.
Risk and Exploitability
The CVSS score of 9.8 marks the vulnerability as critical. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote, as the flaw can be triggered by unauthenticated HTTP requests to the theme’s PHP processing endpoints. An attacker with network access to the site can exploit this remotely to gain full control over the WordPress installation, exfiltrate data, or launch additional attacks against the hosting server. The high severity and remote nature of the exploit underscore the urgency of addressing the vulnerability.
OpenCVE Enrichment