
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27083 is a PHP Object Injection vulnerability caused by improper deserialization of untrusted data in the ThemeREX "Work & Travel Company" WordPress theme. It affects all versions through 1.2 and was published on March 25, 2026, with the vulnerability originally reported on December 10, 2025 by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack, Feedly).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The theme fails to properly validate or sanitize serialized PHP data before deserializing it, allowing an attacker to inject a malicious serialized object via a network request. If a suitable PHP Object/Property (POP) chain exists within the WordPress environment or installed plugins/themes, this can be leveraged to achieve code injection, SQL injection, path traversal, or denial of service. No authentication or user interaction is required, making this exploitable remotely by any unauthenticated attacker (Patchstack).
Successful exploitation can result in full compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. Depending on available POP chains in the environment, an attacker may execute arbitrary code, perform SQL injection, traverse the file system, modify site content, or cause denial of service. The unauthenticated nature of the attack makes it suitable for mass-exploit campaigns targeting large numbers of WordPress sites simultaneously (Patchstack, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, reflecting a currently low but non-negligible probability of exploitation. The vulnerability has not been added to the CISA KEV catalog. However, Patchstack notes that vulnerabilities of this class and severity are frequently used in mass-exploit campaigns against WordPress sites (Patchstack, Feedly).
O:, a:, s:, etc.) in parameters or cookies.unserialize() calls.bash, curl, wget) indicating potential code execution via a POP chain.No official patch from ThemeREX is currently available for the Work & Travel Company theme. Patchstack has issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until an official fix is released. Site owners should immediately audit all installations for theme versions ≤ 1.2, consider disabling or replacing the theme if possible, implement a web application firewall (WAF) rule to block serialized PHP object injection attempts, and monitor for suspicious activity. Upgrading to a patched version should be prioritized as soon as one becomes available (Patchstack).
The vulnerability was credited to researcher Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity and disclosed via Patchstack's coordinated disclosure process. Wordfence referenced the vulnerability in their weekly WordPress vulnerability report for the week of March 9–15, 2026. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database entries (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."