
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27338 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the AivahThemes Car Zone WordPress theme that allows authenticated attackers with low privileges to perform Object Injection. It affects Car Zone versions up to and including 3.7. The vulnerability was reported on December 3, 2025, and published on March 3–5, 2026, with no official patch available at time of disclosure. It carries a CVSS v3.1 base score of 8.8 (High) (Patchstack, Feedly).
The vulnerability stems from unsafe deserialization of user-supplied data within the Car Zone WordPress theme (CWE-502), which can be exploited via the CAPEC-586 Object Injection attack pattern. An authenticated attacker with Subscriber-level privileges can craft a malicious serialized PHP object and submit it over the network, causing the application to deserialize and instantiate it without proper validation. Depending on available PHP classes (gadget chains) present in the WordPress environment, this can lead to arbitrary code execution, file manipulation, or denial of service. The attack requires no user interaction and has low complexity (Patchstack).
Successful exploitation grants an authenticated low-privilege attacker high impact across confidentiality, integrity, and availability — enabling potential remote code execution, sensitive data theft, modification of application behavior, and service disruption. An attacker could leverage code execution to escalate privileges to WordPress administrator, pivot to the underlying server, or deploy web shells for persistent access. The scope is limited to the affected system, but the breadth of impact makes this particularly dangerous for shared hosting environments where many sites may be affected simultaneously (Patchstack, Feedly).
No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class and CVSS score are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack, Feedly).
inurl:wp-content/themes/carzone).unserialize()).O:, a:, or s: patterns); unexpected outbound connections from the web server to external IPs.unserialize() calls.wp-content/themes/carzone/ or wp-content/uploads/); presence of web shells or unfamiliar scripts.apache2, nginx, php-fpm) such as bash, curl, wget, or python; unexpected cron jobs added to the server.No official patch from AivahThemes was available at the time of disclosure; users should monitor the theme's update channel and apply any released patch immediately. As interim mitigations: (1) restrict Subscriber-level and other low-privilege user registrations if not required; (2) deploy a Web Application Firewall (WAF) with rules targeting PHP object injection — Patchstack has issued a virtual patch/mitigation rule for subscribers; (3) consider temporarily deactivating the Car Zone theme until a patch is available; and (4) implement monitoring for suspicious deserialization activity in PHP logs (Patchstack).
The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on December 3, 2025, and disclosed publicly by Patchstack on March 3, 2026. Patchstack classified it as high priority and noted that vulnerabilities of this type are commonly leveraged in mass WordPress exploitation campaigns. No significant broader media coverage or notable researcher commentary beyond the Patchstack disclosure has been observed (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."