Description
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Published: 2026-08-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unauthenticated PHP Object Injection flaw in the FreightCo WordPress theme. Based on the description, it is inferred that an attacker can supply crafted input that causes the theme to instantiate arbitrary PHP objects, which could lead to remote code execution on the affected site. The weakness is identified as CWE-502, which captures vulnerabilities where malicious data is processed as objects.

Affected Systems

Affected systems include the FreightCo theme developed by Theme-Rex for WordPress. All released versions of the theme with a version number less than or equal to 1.1.15 are vulnerable. No other vendors or product lines are listed. Users running these old releases should verify their current theme version and plan an upgrade.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the vulnerability is unauthenticated, meaning an attacker only needs to be able to send a specially crafted HTTP request to the vulnerable WordPress site. Although no EPSS score is available, the lack of a KEV listing does not diminish the high impact. Based on the description, the likely attack vector is through unauthenticated HTTP requests to the vulnerable site, with low complexity and no privileges required. The result could be a full compromise of the WordPress site and the underlying server environment.

Generated by OpenCVE AI on August 24, 2026 at 14:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the FreightCo theme to the latest version (1.1.16 or newer) to apply the fix for the object injection flaw.
  • If an upgrade cannot be applied immediately, deactivate or delete the FreightCo theme to prevent execution of the vulnerable code.
  • Implement a regular update schedule for all WordPress themes and plugins, and monitor Theme-Rex for future security releases.

Generated by OpenCVE AI on August 24, 2026 at 14:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Themerex
Themerex freightco
Wordpress
Wordpress wordpress
Vendors & Products Themerex
Themerex freightco
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Title WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themerex Freightco
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:06.094Z

Reserved: 2026-07-27T14:00:38.499Z

Link: CVE-2026-66650

cve-icon Vulnrichment

Updated: 2026-08-24T12:47:28.831Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T12:16:53.580

Modified: 2026-08-24T16:40:53.647

Link: CVE-2026-66650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data