Impact
The IPharm WordPress theme contains a PHP deserialization flaw that allows untrusted data to be deserialized into objects. Exploitation of this flaw can lead to arbitrary code execution, compromising the integrity, confidentiality, and availability of the affected WordPress site. The vulnerability is classified as CWE-502, indicating a PHP Object Injection weakness.
Affected Systems
ThemeREX Group’s IPharm theme is affected for all releases up to and including version 1.2.4, and any build that has not applied the vendor’s patch beyond this version.
Risk and Exploitability
The CVSS score of 9.8 highlights severe risk, and no EPSS data is published, so the probability cannot be precisely quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves any endpoint that accepts user‑controlled input and passes it to PHP’s unserialize function. An attacker could manipulate serialized objects sent via form data, URLs, or other user‑supplied fields to override object properties or trigger destructive methods. Given the high impact and lack of immediate mitigation from the vendor, remediation should be considered urgent.
OpenCVE Enrichment