Description
Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Deserialization of untrusted input in the Veto theme allows an attacker to instantiate PHP objects whose properties control critical application behavior. When a malicious payload is deserialized, the theme can execute arbitrary PHP code within the context of the WordPress site, compromising confidentiality, integrity, and availability. The vulnerability is classified as CWE-502 and carries a CVSS score of 9.8, indicating a high‑impact remote code execution flaw.

Affected Systems

This flaw affects the WordPress Veto theme published by Axiomthemes, all releases up to and including version 1.6.0. Any WordPress installation that has introduced the Veto theme into its active theme stack is at risk. Users who have not updated the theme beyond the listed version, or who have the theme disabled but still loaded by WordPress, should check whether the vulnerable code is still accessible as part of the site’s file structure.

Risk and Exploitability

The CPES record implies that the vulnerability can be triggered remotely via HTTP requests to the WordPress site. The exploit requires control over the serialized payload, which can be supplied through form fields or URL parameters processed by the theme. Although the EPSS score is not available, the high CVSS rating and lack of KEV listing suggest the flaw is serious but not yet widely exploited in the wild. Operators should assume a moderate to high likelihood of exploitation, especially in environments with publicly accessible WordPress sites that have the Veto theme enabled.

Generated by OpenCVE AI on October 10, 2026 at 08:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Veto theme to the latest supported version (any release above 1.6.0) or replace it with an alternative theme.
  • Disable or remove the Veto theme from WordPress if an upgrade is not immediately possible, ensuring it is not active or loaded by the site.
  • Sanitize and validate all serialized data before it reaches the theme processing code; consider disabling PHP object serialization if the theme does not require it.
  • Apply general WordPress hardening practices, such as restricting upload permissions, using a web application firewall, and ensuring the site runs the latest core WordPress version.

Generated by OpenCVE AI on October 10, 2026 at 08:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
Title WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:34.675Z

Reserved: 2026-09-19T00:23:25.964Z

Link: CVE-2026-93927

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:05.050

Modified: 2026-10-10T08:17:05.050

Link: CVE-2026-93927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data