Impact
The Hygia theme for WordPress (ThemeREX Group) contains a deserialization of untrusted data flaw that enables PHP object injection. This weakness allows an attacker to craft a serialized payload that, when processed by the theme, can instantiate arbitrary PHP objects and execute arbitrary code. The CVSS score of 9.8 reflects the severity of this remote code execution potential and the significant impact on confidentiality, integrity, and availability of the affected site.
Affected Systems
WordPress sites using the ThemeREX Group Hygia theme, versions up to and including 1.21.0.
Risk and Exploitability
The CVSS score of 9.8 indicates an extremely high severity. The EPSS score is not available, but the absence of a listing in the CISA KEV catalog does not reduce the risk; the flaw is exploitation‑ready as it does not require privileged access or special conditions. Based on the description, it is inferred that an attacker can trigger the vulnerability by submitting a crafted serialized payload through a request that the theme processes, potentially from any user with access to the vulnerable input channel.
OpenCVE Enrichment