Impact
Deserialization of untrusted data in the WordPress Tantra theme enables PHP Object Injection, classified as CWE‑502. The flaw permits an attacker to construct malicious serialized objects which, when processed by the theme, can compromise the entire WordPress site, leading to data tampering, privilege escalation, or full server control.
Affected Systems
The issue affects the ThemeREX Group Tantra WordPress theme in all releases up to and including version 2.9.0. This includes every earlier version of the theme distributed by ThemeREX Group. Any website deploying Tantra 2.9.0 or older is potentially impacted.
Risk and Exploitability
The CVSS score of 9.8 reflects a high severity and indicates that exploitation is feasible with significant impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog as of the latest assessment. The likely attack vector is remote, through crafted HTTP requests that pass serialized payloads to the theme’s deserialization routines. Although the exact execution path requires that deserialized data be accepted and instantiated by the theme, the nature of PHP object injection generally allows arbitrary code execution when the attacker can influence the serialized content.
OpenCVE Enrichment