Impact
The vulnerability is an unauthenticated PHP Object Injection in all Accalia theme versions 1.5.3 and earlier. An attacker can inject crafted serialized PHP objects that are processed by the theme, resulting in arbitrary code execution under the web server’s permissions. This flaw exposes the entire WordPress site to compromise, including data exfiltration, modification, or the installation of backdoors. The weakness is identified as CWE-502.
Affected Systems
The Accalia theme, released by AncoraThemes, is affected in all releases up to version 1.5.3. WordPress sites that have installed any of these versions are therefore vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV, implying it has not yet been confirmed in the wild. The flaw is unauthenticated and accepts serialized input from public-facing endpoints, so an attacker only needs to supply the malicious payload via crafted requests or URLs, requiring no special credentials.
OpenCVE Enrichment