Impact
The vulnerability is a deserialization of untrusted data flaw that allows PHP object injection within the WordPress Smart Casa theme. It falls under CWE‑502 and can enable an attacker to manipulate serialized data structures, potentially leading to arbitrary code execution on the server. The impact is the ability for a malicious actor to gain full control over the affected WordPress site.
Affected Systems
WordPress installations using the Smart Casa theme from any version before 1.0.13, including the earliest undisclosed release up to and including 1.0.12, are affected. The risk applies to all sites that have the theme activated.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and while EPSS data is not available, the high base score and the nature of the flaw suggest a realistic exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is server‑side; an attacker can supply crafted serialized payloads through the theme’s input handling or via malformed requests to trigger the insecure deserialization logic. No additional authentication or elevated privileges are required beyond what the standard theme grants, implying a wide potential impact.
OpenCVE Enrichment