Impact
The vulnerability is an unauthenticated PHP Object Injection flaw in the Advice WordPress theme up to version 1.18.0, allowing malicious serialized data to be processed without proper validation and potentially leading to arbitrary code execution and full compromise of the web application.
Affected Systems
WordPress sites that have the Advice theme installed from AncoraThemes, version 1.18.0 or earlier, are affected. No other plugins or theme versions are mentioned as impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a severe risk, while the EPSS score is not available, leaving the exploitation probability uncertain. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote: an attacker can send crafted serialized payloads to an endpoint of the theme without authentication, triggering the injection.
OpenCVE Enrichment