
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27082 is a PHP Object Injection vulnerability caused by deserialization of untrusted data in the ThemeREX Love Story WordPress theme. It affects all versions up to and including 1.3.12 and was published on March 25, 2026, with the vulnerability originally reported on December 10, 2025 by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), requiring no authentication or user interaction and exploitable over the network (Patchstack).
The root cause is improper deserialization of untrusted data (CWE-502) within the Love Story WordPress theme, enabling PHP Object Injection (CAPEC-586). An unauthenticated remote attacker can supply a crafted serialized PHP object via a network-accessible endpoint; if a suitable PHP Object Property (POP) chain exists within the WordPress environment, this can be leveraged to achieve arbitrary code execution, SQL injection, path traversal, or denial of service. No authentication or user interaction is required, and attack complexity is low (Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, with high impacts to confidentiality, integrity, and availability. Depending on available POP chains in the environment, an attacker could achieve arbitrary code execution, perform SQL injection, traverse the file system, or cause a denial of service condition. This could enable lateral movement within shared hosting environments or lead to complete site takeover and data exfiltration (Patchstack).
As of the time of reporting, no public proof-of-concept exploit code has been observed and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.024%, reflecting low current exploitation probability. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates it high priority and notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
style.css files.O:[0-9]+:" in request bodies or parameters).wp-content/uploads; presence of web shells (e.g., files named shell.php, cmd.php, or similar).bash, curl, wget, python) indicating command execution via deserialization.No official patch from ThemeREX is currently available for the Love Story theme. Site administrators should update to a version newer than 1.3.12 if and when one becomes available, and monitor ThemeREX for security updates. As an interim measure, Patchstack has issued a virtual patch/mitigation rule to block exploitation attempts for subscribers. Additional workarounds include deploying a Web Application Firewall (WAF) with rules to detect and block serialized PHP object injection, restricting access to affected theme functionality, and conducting security audits on sites running affected versions (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the period of March 9–15, 2026, highlighting it as part of broader WordPress ecosystem security monitoring. Patchstack, which coordinated the disclosure, has issued a virtual mitigation rule and rates the vulnerability as high priority due to the potential for mass exploitation campaigns targeting WordPress sites. No significant additional vendor statements or notable researcher commentary beyond the initial disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."