Impact
The vulnerability is a deserialization of untrusted data, allowing PHP object injection in the Edema WordPress theme. This weakness is a classic example of CWE-502 and can enable attackers to execute arbitrary code or inject malicious objects that persist across requests. The potential impact is full compromise of the target website, including data theft, defacement, or further lateral movement within the hosting environment. The description does not specify the exact privileges gained, but given the nature of object injection, an attacker could likely elevate to any permissions the WordPress user running the theme possesses.
Affected Systems
Angular vendor ThemeREX Group’s Edema theme for WordPress is affected, with all releases from the initial public version up through 1.2.2.2 susceptible to the flaw. Versions prior to 1.2.2.2 and any releases beyond that point contain the remediation. Site owners running any of the vulnerable theme versions should identify their installation and verify the current version number.
Risk and Exploitability
The CVSS score of 9.8 indicates the flaw is considered Critical, and the vulnerability is not listed in the CISA KEV catalog, though the EPSS score is not available. Because the flaw occurs during deserialization of user‑controlled data, the likely attack vector is remote, with an attacker crafting a manipulated payload in a HTTP request that reaches the theme’s processing endpoint. Such an attack does not appear to require privileged access beyond normal web traffic, making it potentially exploitable by anyone who can access the site. The absence of an EPSS rating does not diminish the criticality implied by the CVSS score, and administrators should treat the vulnerability as a high‑risk exposure until resolved.
OpenCVE Enrichment