Impact
This vulnerability is a deserialization of untrusted data that allows an attacker to inject malicious objects into the PHP runtime. The flaw could enable the attacker to execute arbitrary code or manipulate the application state, resulting in full compromise of the affected WordPress site. The impact is high, reflected in a CVSS score of 9.8, and the weakness is categorized as CWE-502.
Affected Systems
The affected product is the WordPress Rosalinda theme developed by ThemeREX Group. Versions up through 1.2.4 (inclusive) are vulnerable; the vulnerability does not apply to releases newer than 1.2.4.
Risk and Exploitability
The absence of an EPSS score and lack of listing in the CISA KEV catalog do not diminish the risk, as the CVSS score indicates a severe flaw that can be exploited with moderate effort. The likely attack vector involves supplying crafted serialized input to the theme’s processing routines, which will accept and unserialize the data without proper validation. An attacker who can influence this input – for example, via a form, URL parameter, or embedded content – can trigger the injection and potentially execute code with the permissions of the WordPress instance.
OpenCVE Enrichment