Impact
An unauthenticated PHP Object Injection flaw exists in the Abogado theme for WordPress versions 1.18 and earlier. The vulnerability allows an attacker to craft malicious serialized PHP data that is processed by the theme, leading to arbitrary code execution on the web server. The flaw is categorized as CWE-502, indicating improper handling of object serialization.
Affected Systems
All installations that use AncoraThemes' Abogado theme with a version number less than or equal to 1.18 are vulnerable. The issue impacts the WordPress site itself and can affect any user who has access to the theme’s serialization endpoints. No specific operating system or PHP version was mentioned, so the vulnerability is likely present on any environment running the affected theme.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as Critical, meaning that an attacker can fully compromise the affected WordPress installation. The attack vector is unauthenticated; anyone who can send a crafted HTTP request to the site could exploit it. Although no EPSS score is available, the high severity suggests a high likelihood of exploitation if the vulnerability is not patched, and the vulnerability is not yet listed in the CISA KEV catalog, leaving it potentially unmonitored by existing threat intelligence feeds.
OpenCVE Enrichment