Impact
The vulnerability arises because the Dwell theme deserializes data supplied without validation, allowing PHP object injection. An attacker who can deliver a crafted serialized object to the theme can execute arbitrary PHP code on the WordPress site, compromising confidentiality, integrity, and availability. The flaw is triggered by normal theme functionality that processes user or request‑supplied data, providing a path for the malicious payload to be decoded and executed.
Affected Systems
WordPress sites that have installed ThemeREX Group’s Dwell theme at version 1.16.0 or earlier are affected; any instance of the theme before the latest release remains vulnerable.
Risk and Exploitability
The high CVSS score of 9.8 signals that this flaw can be exploited remotely with user interaction. Although the EPSS score is not listed, the absence of a CISA KEV entry suggests no known widespread exploitation yet, yet the remote code execution potential still represents a critical threat. An attacker could inject malicious code by sending a crafted serialized payload through a web request or an input field processed by the theme, gaining full control of the affected WordPress installation.
OpenCVE Enrichment