Impact
Deserialization of untrusted data in the Partiso theme leads to PHP Object Injection, allowing an attacker to create arbitrary objects and execute malicious PHP code. This flaw arises when the theme unserializes data that can be supplied by a user, enabling full code execution on the affected WordPress site.
Affected Systems
Any installation of the Partiso theme from ThemeREX Group that uses any version up to and including 1.1.13 is potentially vulnerable. The issue affects all prior releases for which a specific release version is not documented.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as Critical, indicating that if exploited, an attacker could gain unrestricted code execution on the host. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: a crafted serialized payload can be delivered through a web request that triggers the theme’s deserialization logic, enabling an attacker to remotely exercise the vulnerability without other prerequisites.
OpenCVE Enrichment