
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25359 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the Pendulum WordPress theme developed by rascals. It affects all versions of the Pendulum theme prior to 3.1.5. The vulnerability was published on March 25, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low privileges and no user interaction to exploit over the network (Feedly, Patchstack).
The root cause is improper handling of serialized PHP data, classified as CWE-502 (Deserialization of Untrusted Data), which maps to CAPEC-586 (Object Injection). An attacker with low-level authenticated access can supply crafted serialized PHP objects to the vulnerable theme, which are then deserialized without adequate validation or sanitization. This allows the attacker to instantiate arbitrary PHP objects, potentially chaining existing class methods (gadget chains) within the WordPress environment to achieve code execution or other malicious outcomes (Feedly).
Successful exploitation can result in complete system compromise, with HIGH impact across all three security dimensions: confidentiality (unauthorized access to sensitive data), integrity (modification of data and system files), and availability (potential denial of service or system disruption). Because the attack requires only low privileges, any authenticated WordPress user — such as a subscriber — could potentially leverage this vulnerability to escalate privileges or take full control of the affected WordPress installation (Feedly).
As of the time of reporting, there is no public proof-of-concept (PoC) exploit available and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low privilege requirement and network-accessible attack vector make it an attractive target if a PoC is published (Feedly).
O:, a:, or s: in POST bodies or cookies) sent to WordPress endpoints associated with the Pendulum theme.wp-content/themes/pendulum/) or uploads directory; modification timestamps on core WordPress files that do not align with legitimate updates.apache2, nginx, php-fpm) such as bash, curl, wget, or reverse shell processes.The primary remediation is to upgrade the Pendulum WordPress theme to version 3.1.5 or later, which contains the fix for this vulnerability. Site administrators should apply this update immediately given the high CVSS score and low exploitation barrier. As a temporary measure, consider restricting user registration or limiting low-privileged user access to affected theme functionality until the patch is applied. Additionally, deploying a Web Application Firewall (WAF) with rules to detect and block PHP object injection payloads can provide an additional layer of defense (Feedly, Patchstack).
The vulnerability was covered in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the period of March 16–22, 2026, indicating it received standard industry attention as part of routine WordPress security monitoring (Wordfence). It was also catalogued by VulDB shortly after disclosure. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."