Impact
Deserialization of untrusted data in the Convex theme allows an attacker to instantiate arbitrary PHP objects, potentially leading to remote code execution. The flaw is cataloged as CWE-502 and scored 9.8 on CVSS, indicating a critical vulnerability. The vulnerability arises from the theme’s handling of user‑supplied serialized data without proper validation or sanitization.
Affected Systems
All WordPress sites using ThemeREX Group’s Convex theme version 1.16.0 or earlier are affected. The problem exists in all documented releases up to and including 1.16.0, irrespective of the WordPress core version.
Risk and Exploitability
Given the CVSS score of 9.8, the risk to affected installations is very high. The EPSS score is not available, so the exact likelihood of exploitation remains uncertain, but the absence of KEV listing does not mean the vulnerability is not being used; attackers could craft HTTP requests targeting the theme’s serialization logic. Because the flaw involves PHP object injection, a successful exploit would give the attacker code execution privileges on the server, compromising confidentiality, integrity, and availability of the entire WordPress installation.
OpenCVE Enrichment