Description
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Axiomthemes Balance theme versions up to 1.12.0 allow PHP object injection through uncontrolled deserialization of data. This flaw, identified as CWE‑502, can enable an attacker to execute arbitrary PHP code or manipulate the application’s internal state, potentially compromising the entire WordPress site.

Affected Systems

All WordPress installations running the Balance theme version 1.12.0 or earlier are affected. Users who have not upgraded beyond 1.12.0 are exposed.

Risk and Exploitability

With a CVSS score of 9.8, the vulnerability poses a critical risk. Although EPSS data is unavailable, the absence from the KEV catalog does not reduce the threat; the flaw remains exploitable from any remote location that can deliver crafted serialized objects to the vulnerable theme. Sites that expose the theme’s public interfaces are at highest risk.

Generated by OpenCVE AI on October 10, 2026 at 08:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Balance theme to the latest version (1.13.0 or later) to eliminate the vulnerable deserialization code.
  • If an immediate upgrade is not possible, stop using the vulnerable theme by switching to an alternative or disabling it entirely.
  • Remove or whitelist any custom PHP serialization handling used by the theme and ensure that any future data passed to unserialize() comes from trusted sources.

Generated by OpenCVE AI on October 10, 2026 at 08:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
Title WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:38.671Z

Reserved: 2026-09-19T00:23:25.965Z

Link: CVE-2026-93945

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:07.057

Modified: 2026-10-10T08:17:07.057

Link: CVE-2026-93945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data