Impact
Axiomthemes Balance theme versions up to 1.12.0 allow PHP object injection through uncontrolled deserialization of data. This flaw, identified as CWE‑502, can enable an attacker to execute arbitrary PHP code or manipulate the application’s internal state, potentially compromising the entire WordPress site.
Affected Systems
All WordPress installations running the Balance theme version 1.12.0 or earlier are affected. Users who have not upgraded beyond 1.12.0 are exposed.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability poses a critical risk. Although EPSS data is unavailable, the absence from the KEV catalog does not reduce the threat; the flaw remains exploitable from any remote location that can deliver crafted serialized objects to the vulnerable theme. Sites that expose the theme’s public interfaces are at highest risk.
OpenCVE Enrichment