Impact
The vulnerability arises from the Smash theme’s handling of deserialized data, allowing an attacker to inject a crafted PHP object. This object injection can trigger PHP magic methods, resulting in arbitrary code execution on the WordPress site. The flaw is a classic PHP Object Injection, at its core it permits remote attackers to execute code with the permissions of the web server when the theme processes untrusted input.
Affected Systems
The affected product is the Smash WordPress theme developed by ThemeREX Group. All released versions up to and including version 1.12.0 are vulnerable. WordPress sites that have these versions of the Smash theme installed are at risk.
Risk and Exploitability
The metric set assigns a CVSS score of 9.8, signifying a very high severity. Exploit probability data (EPSS) is not available, but the lack of KEV listing does not preclude exploitation. Because the flaw occurs during the theme’s deserialization of user‑supplied data, the likely attack vector is remote; an attacker can craft a request containing a malicious serialized payload and deliver it to the site. Once processed, the injection can lead to code execution or privilege escalation on the host, making this a critical risk for any affected WordPress deployment.
OpenCVE Enrichment