Impact
Deserialization of untrusted data in the WordPress Let's Play theme allows an attacker to inject malicious PHP objects. When an object is deserialized without proper validation, the theme can instantiate arbitrary classes, leading to execution of unintended code. This flaw is a classic PHP Object Injection, classified under CWE-502, and can compromise the confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The vulnerability affects the Let's Play theme distributed by ThemeREX Group. All versions from the earliest release up to and including 1.1.15 are affected. WordPress sites that have this theme installed and are accessible via the web are at risk.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity. The EPSS score is not available, but the lack of a listed KEV record suggests exploit activity is not yet widespread; however, the nature of PHP deserialization in a public website gives attackers ample opportunity. The likely attack vector is a remote web request that includes crafted serialized data, such as via POST parameters or query strings. Successful exploitation would allow the attacker to execute arbitrary code on the server, giving full control over the site and possibly the underlying server environment.
OpenCVE Enrichment