Impact
The vulnerability is an unauthenticated PHP Object Injection flaw in the FreightCo WordPress theme. Based on the description, it is inferred that an attacker can supply crafted input that causes the theme to instantiate arbitrary PHP objects, which could lead to remote code execution on the affected site. The weakness is identified as CWE-502, which captures vulnerabilities where malicious data is processed as objects.
Affected Systems
Affected systems include the FreightCo theme developed by Theme-Rex for WordPress. All released versions of the theme with a version number less than or equal to 1.1.15 are vulnerable. No other vendors or product lines are listed. Users running these old releases should verify their current theme version and plan an upgrade.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the vulnerability is unauthenticated, meaning an attacker only needs to be able to send a specially crafted HTTP request to the vulnerable WordPress site. Although no EPSS score is available, the lack of a KEV listing does not diminish the high impact. Based on the description, the likely attack vector is through unauthenticated HTTP requests to the vulnerable site, with low complexity and no privileges required. The result could be a full compromise of the WordPress site and the underlying server environment.
OpenCVE Enrichment