Impact
The WordPress Camelia theme contains a deserialization vulnerability that allows an attacker to inject PHP objects through untrusted input. This flaw can lead to arbitrary code execution on the server, compromising the confidentiality, integrity, and availability of the affected WordPress site. The weakness is classified as CWE‑502, a deserialization of untrusted data issue.
Affected Systems
WordPress sites that use the Camelia theme from ThemeREX Group, specifically versions 1.2.15 and earlier, are affected. Any installation running those versions without the latest patch is vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 9.8, indicating a high risk level. No EPSS information is provided and the vulnerability is not listed in the CISA KEV catalog, however the severity and known exploitation of PHP object injection suggest a strong likelihood of exploitation in a realistic attack scenario. The likely attack vector involves supplying maliciously crafted input that is deserialized by the theme, enabling code execution. Administrators should assume the vulnerability could be exploited remotely if the theme processes data from untrusted sources.
OpenCVE Enrichment