Impact
The vulnerability arises from unsafe deserialization of data supplied by users, allowing an attacker to instantiate arbitrary PHP objects within the Hogwords WordPress theme; this flaw can lead to remote code execution on the affected site and is classified as CWE-502, deserialization of untrusted data.
Affected Systems
ThemeREX Group's Hogwords theme, versions 1.2.7 and earlier, are affected. Any installation of Hogwords up to and including 1.2.7 is vulnerable, regardless of minor patch releases. Versions newer than 1.2.7 are presumed not to contain the flaw.
Risk and Exploitability
With a CVSS score of 9.8, this issue is considered extremely severe. No EPSS data is available, and the vulnerability is not currently listed in the CISA KEV catalogue. Attackers would need to supply malicious serialized data that is processed by the theme; the vector is most likely through web requests accepted by the theme, such as form submissions or cookie data. This defect can be exploited by anyone who can influence the data that the theme deserializes, potentially allowing arbitrary code execution on the server.
OpenCVE Enrichment