
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27417 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the SeventhQueen Sweet Date WordPress theme. It affects all versions of the Sweet Date theme prior to 4.0.1 and was published on March 5, 2026, with the CVE assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its network-accessible, unauthenticated, and no-user-interaction-required attack profile (Feedly, Patchstack).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The Sweet Date WordPress theme fails to safely handle serialized PHP data, allowing an unauthenticated remote attacker to supply crafted serialized input that is deserialized by the application, resulting in PHP object injection. Depending on available PHP classes (gadget chains) present in the WordPress environment, this can be escalated to arbitrary code execution, file manipulation, or other critical impacts (Feedly, Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker could achieve remote code execution, exfiltrate sensitive data (including credentials and user information), modify or delete site content, or use the compromised server as a pivot point for further attacks. No authentication or user interaction is required, making this exploitable at scale against any unpatched installation (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score and zero-authentication requirement make it a high-priority patching target.
style.css files.O:, a:, s:) sent to Sweet Date theme endpoints; unexpected outbound connections from the web server to external IPs.unserialize() calls.wp-config.php or core WordPress files.bash, curl, wget, python) indicating command execution via deserialization gadget chains.The vendor SeventhQueen has released Sweet Date version 4.0.1, which addresses this vulnerability. All users running versions prior to 4.0.1 should upgrade immediately. No configuration-based workaround is documented; upgrading to 4.0.1 or later is the only recommended remediation (Feedly, Patchstack). As an interim measure, consider using a web application firewall (WAF) with rules to detect and block serialized PHP object injection attempts.
The vulnerability was highlighted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the period of February 23 – March 1, 2026, indicating it received attention from the WordPress security community (Wordfence). Patchstack, the assigning CNA, published the advisory as part of their ongoing WordPress theme vulnerability disclosure program. No significant broader media coverage or notable researcher commentary beyond standard advisory publication has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."