Impact
The vulnerability is a deserialization of untrusted data flaw in the Travesia WordPress theme, allowing an attacker to inject a malicious PHP object. An attacker who can supply crafted serialized input can trigger arbitrary code execution within the theme context, potentially compromising site data and the underlying server. The flaw is classified as insecure deserialization and is rated CVSS 9.8, indicating a critical risk.
Affected Systems
ThemeREX Group’s Travesia theme, from its initial release through version 1.1.16, is affected. Any WordPress site deploying any version of Travesia up to and including 1.1.16 remains vulnerable until the theme is upgraded past this point.
Risk and Exploitability
The CVSS base score of 9.8 reflects that the vulnerability can be exploited without authentication and with an attacker‑controlled input. Although no EPSS value is provided, the high severity and lack of mitigation in the current theme suggest a high likelihood of exploitation if the vulnerability is public. The vulnerability is not listed in the CISA KEV catalogue, but the attack vector is inferred to be through any user‑supplied serialized data handled by the theme, likely via HTTP requests or form submissions. No additional prerequisites are noted in the provided description.
OpenCVE Enrichment