Impact
Deserialization of untrusted input in the Veto theme allows an attacker to instantiate PHP objects whose properties control critical application behavior. When a malicious payload is deserialized, the theme can execute arbitrary PHP code within the context of the WordPress site, compromising confidentiality, integrity, and availability. The vulnerability is classified as CWE-502 and carries a CVSS score of 9.8, indicating a high‑impact remote code execution flaw.
Affected Systems
This flaw affects the WordPress Veto theme published by Axiomthemes, all releases up to and including version 1.6.0. Any WordPress installation that has introduced the Veto theme into its active theme stack is at risk. Users who have not updated the theme beyond the listed version, or who have the theme disabled but still loaded by WordPress, should check whether the vulnerable code is still accessible as part of the site’s file structure.
Risk and Exploitability
The CPES record implies that the vulnerability can be triggered remotely via HTTP requests to the WordPress site. The exploit requires control over the serialized payload, which can be supplied through form fields or URL parameters processed by the theme. Although the EPSS score is not available, the high CVSS rating and lack of KEV listing suggest the flaw is serious but not yet widely exploited in the wild. Operators should assume a moderate to high likelihood of exploitation, especially in environments with publicly accessible WordPress sites that have the Veto theme enabled.
OpenCVE Enrichment