
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22454 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the ThemeREX Solaris WordPress theme, affecting all versions through 2.5. Discovered by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and reported on December 4, 2025, it was publicly disclosed on March 3–5, 2026. No official patch is currently available. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The ThemeREX Solaris theme fails to properly validate or sanitize serialized PHP data before deserializing it, allowing an unauthenticated remote attacker to inject malicious PHP objects. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service. No authentication, user interaction, or special privileges are required to exploit this flaw (Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. Depending on available POP chains in the environment, an attacker could achieve remote code execution, exfiltrate sensitive data, manipulate the database via SQL injection, traverse the file system, or cause a denial of service. The unauthenticated, network-accessible nature of the flaw makes it suitable for mass-exploit campaigns targeting large numbers of WordPress sites simultaneously (Patchstack).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of near-term exploitation, though the critical CVSS score and unauthenticated attack vector elevate risk. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has noted that vulnerabilities of this class are frequently used in mass-exploit campaigns against WordPress sites (Patchstack).
O:, a:, s: typical of PHP serialization).__wakeup, __destruct, __toString).wp-content/themes/solaris/ directory or wp-content/uploads/; presence of web shells or unfamiliar scripts.bash, curl, wget, python) following HTTP requests to the theme's endpoints.No official patch from ThemeREX is currently available for the Solaris theme. As an immediate measure, site owners should disable or remove the Solaris theme if it is not essential. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until an official fix is released. Organizations should monitor application logs for serialized object injection attempts and consider placing a Web Application Firewall (WAF) rule to block PHP serialized data in user-supplied inputs (Patchstack).
Wordfence included CVE-2026-22454 in its weekly WordPress vulnerability report for the period of March 2–8, 2026, highlighting it among notable disclosures for that week (Wordfence). The vulnerability was also catalogued by VulDB shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."