Impact
The Greeny WordPress theme contains a PHP Object Injection vulnerability caused by the deserialization of untrusted data. This flaw permits malicious actors to craft serialized payloads that, when processed by the theme, can lead to the execution of arbitrary PHP code on the hosting server. The resulting impact is the potential acquisition of full control over the WordPress installation, compromising confidentiality, integrity and availability.
Affected Systems
This vulnerability affects ThemeREX Group's Greeny theme, specifically all releases up to and including version 2.10.0. Any WordPress site that has the Greeny theme installed and is running one of those versions is potentially susceptible to exploitation.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating a critical severity. The EPSS score is not available, so the historical exploitation frequency is unknown. The vulnerability is not listed in the CISA KEV catalog, but based on the description it is inferred that an attacker can trigger the flaw by sending malicious serialized data to the theme, potentially via a crafted HTTP request that includes the payload. This inference is not explicitly confirmed by the CVE data. The risk remains high for any exposed site with the vulnerable theme active.
OpenCVE Enrichment