
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22497 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the AncoraThemes Jardi WordPress theme. It affects all versions of the Jardi theme through 1.7.2 and allows unauthenticated remote attackers to inject malicious PHP objects without any user interaction. The vulnerability was published on March 5, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Patchstack).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The vulnerability arises from the Jardi theme's unsafe deserialization of user-supplied data, allowing an attacker to craft a malicious serialized PHP object and submit it to the application without authentication or user interaction. If a suitable PHP "gadget chain" exists within the WordPress installation (either in the theme, core, or installed plugins), the deserialized object can trigger arbitrary code execution or other destructive operations (Feedly, Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker could achieve remote code execution, gain unauthorized access to sensitive data, modify site content or configuration, install backdoors, or disrupt service availability. The network-accessible attack vector and lack of authentication requirements significantly broaden the potential attack surface (Feedly).
As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Feedly).
/wp-content/themes/jardi/) or using tools like WPScan.O:<number>:"<classname>") in POST bodies, cookies, or query parameters targeting the Jardi theme endpoints./wp-content/uploads/, /wp-content/themes/jardi/); modification timestamps on core WordPress files that do not align with legitimate updates.unserialize() calls.apache2, nginx, php-fpm) such as bash, curl, wget, or python; outbound network connections from the web server to unknown external IPs.The primary remediation is to update the Jardi theme to a version newer than 1.7.2 as soon as a patched release becomes available from AncoraThemes. If no patch is currently available, consider temporarily deactivating and removing the Jardi theme and switching to an alternative. Deploying a Web Application Firewall (WAF) with rules targeting PHP object injection patterns can help reduce exploitation risk in the interim. Monitor Patchstack and AncoraThemes for security advisories and apply updates promptly upon release (Feedly, Patchstack).
Wordfence included CVE-2026-22497 in its weekly WordPress vulnerability report for the period of March 2–8, 2026, highlighting it among notable theme vulnerabilities (Wordfence). The vulnerability was also tracked by VulDB and automated CVE notification services shortly after disclosure. No significant independent researcher commentary or broader media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."