Impact
The Agricola WordPress theme includes an unauthenticated PHP Object Injection flaw that lets an attacker instantiate arbitrary PHP objects. This can lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected WordPress site. The weakness is categorized as CWE‑502, which signifies improper deserialization of untrusted data.
Affected Systems
AxiomThemes’ Agricola theme versions 1.21.0 and earlier are vulnerable. Sites using these theme versions are at risk if the theme is active and accessible to unauthenticated users.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability is considered critical. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, but the high severity and the ability to exploit the flaw without authentication imply a high likelihood of exploitation. The attack vector is likely remote, where a malicious user sends crafted data to a WordPress endpoint that processes object serialization within the theme.
OpenCVE Enrichment