
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22473 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) affecting the designthemes Dental Clinic WordPress theme in versions up to and including 3.7. It was reported on December 7, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and publicly disclosed on March 4–5, 2026. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), requiring only low-privilege authenticated access to exploit (Patchstack, Feedly).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which enables PHP Object Injection (CAPEC-586). An authenticated attacker with Subscriber-level privileges can pass a crafted serialized PHP object to a vulnerable input, which the theme deserializes without adequate validation. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service (Patchstack, Feedly).
Successful exploitation could result in complete compromise of the affected WordPress site, including unauthorized access to sensitive data (confidentiality), modification or destruction of content and database records (integrity), and disruption of site availability. The actual severity of impact depends on the presence of a usable POP chain in the environment; with one present, attackers could achieve remote code execution, escalate privileges, or pivot to other systems hosted on the same server (Patchstack, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability was detected by Qualys (detection ID 531085) and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns once weaponized (Patchstack, Feedly).
/wp-admin/admin-ajax.php) or theme-specific endpoints containing serialized PHP data (strings beginning with O:, a:, s: patterns)./wp-content/themes/dental/) or uploads directory; modified core WordPress files.bash, curl, wget, python) indicating potential code execution via a POP chain.wp_options), new administrator accounts, or modified user roles in the database.As of the disclosure date, no official patch from the theme developer (designthemes) is available for the Dental Clinic theme. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site owners should immediately consider deactivating or replacing the theme if possible, restricting user registration to prevent unauthorized Subscriber-level accounts, and deploying a Web Application Firewall (WAF) with rules targeting PHP deserialization payloads. Monitoring system logs for suspicious serialized object submissions is also recommended (Patchstack, Feedly).
The vulnerability was credited to researcher Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, who reported it through Patchstack's coordinated disclosure process. Patchstack classified it as high priority, noting that PHP Object Injection vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media discussion beyond automated CVE notification channels (e.g., CVEnew on Twitter/Nitter) has been observed (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."