
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22453 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the ThemeREX Pets Club WordPress theme. It affects all versions of the Pets Club theme through version 2.3. The vulnerability was published on March 5, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its unauthenticated, network-exploitable nature with no user interaction required (Feedly, Patchstack).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The root cause is improper handling of serialized PHP data within the Pets Club theme, allowing an attacker to supply crafted serialized objects that are deserialized server-side without validation. Because no authentication or privileges are required and the attack vector is network-accessible, an unauthenticated remote attacker can submit malicious serialized payloads to trigger object injection. Depending on available PHP classes (gadget chains) in the WordPress environment, this can escalate to arbitrary code execution (Feedly, Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An attacker achieving arbitrary code execution could exfiltrate sensitive data (e.g., database credentials, user PII), modify or delete site content, install backdoors or web shells, and potentially pivot to the underlying server or hosting environment. The unauthenticated, network-accessible nature of the vulnerability means any internet-facing WordPress site running Pets Club ≤ 2.3 is at risk without any user interaction (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It has been detected by Qualys (detection ID 531058) and reported in the Wordfence weekly WordPress vulnerability report for the week of March 2–8, 2026 (Wordfence, Qualys).
O:<length>:"<classname>") in POST bodies, cookies, or query parameters targeting the Pets Club theme endpoints; unexpected outbound connections from the web server to external IPs..php files in /wp-content/uploads/ or theme directories.O:, a:, s:) in parameters; PHP error logs referencing unexpected class instantiation or __wakeup/__destruct method calls.bash, sh, curl, wget, python) indicating command execution via deserialization gadget chains.No official patch has been confirmed as available for the ThemeREX Pets Club theme at the time of reporting (Feedly). Recommended actions include:
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for March 2–8, 2026, highlighting it as part of a broader set of critical WordPress theme and plugin issues (Wordfence). Qualys added detection for this CVE as part of its March 2026 application security detections update (Qualys). The CVE was also noted on VulDB and via automated CVE notification channels on social media shortly after publication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."