Impact
Unvalidated deserialization in WordPress Abelle theme versions 1.22 and earlier allows an unauthenticated attacker to send crafted PHP serialized objects, giving the ability to instantiate arbitrary PHP classes and execute code. The flaw is classified as CWE-502. Successful exploitation would compromise the confidentiality, integrity, and availability of the affected site, enabling full control over the WordPress installation.
Affected Systems
The vulnerability affects WordPress sites that have the ThemeREX Abelle theme installed with a version of 1.22 or earlier.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is considered Critical. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a web request to the affected theme’s components, which does not require authentication and can be automated by malicious actors.
OpenCVE Enrichment