
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27437 is a Deserialization of Untrusted Data vulnerability in the ThemeREX Tennis Club WordPress theme (plugin slug: tennis-sportclub) that allows unauthenticated attackers to perform PHP Object Injection. All versions through 1.2.3 are affected. The vulnerability was published on March 5, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its unauthenticated, network-exploitable nature (Feedly, Patchstack).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The vulnerability arises when the Tennis Club theme deserializes user-supplied input without adequate validation or sanitization, allowing an attacker to craft a malicious serialized PHP object that is processed by the application. No authentication or user interaction is required, and the attack is executable remotely over the network with low complexity. Depending on available PHP classes (gadget chains) present in the WordPress environment, successful object injection can escalate to arbitrary code execution, file manipulation, or other critical impacts (Feedly, Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress installation, with high impact to confidentiality, integrity, and availability. An unauthenticated remote attacker could achieve arbitrary code execution by leveraging PHP gadget chains, potentially enabling webshell deployment, data exfiltration, database access, or full server takeover. The vulnerability also poses a risk of lateral movement within shared hosting environments where multiple sites reside on the same server (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated, zero-interaction attack vector makes it a high-priority target if a PoC becomes public (Feedly).
unserialize()).O:, a:, s: followed by numeric length indicators); unexpected outbound connections from the web server process.__wakeup, __destruct, __toString).eval, base64_decode, system, exec patterns).php, bash, curl, wget) performing unexpected network or file operations.No patch has been released for the ThemeREX Tennis Club theme as of the disclosure date; users should monitor the theme's repository for an update beyond version 1.2.3. As an immediate workaround, administrators should deactivate and remove the Tennis Club theme if it is not essential, or restrict access to the WordPress installation at the network level (e.g., via WAF rules blocking serialized PHP object patterns). Applying the principle of least privilege to the web server account and enabling a Web Application Firewall (WAF) with PHP deserialization detection rules can reduce exploitation risk. Organizations should also audit other installed plugins and themes for similar vulnerabilities (Feedly, Patchstack).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report covering the period of February 23 to March 1, 2026, indicating it received standard industry tracking as part of routine WordPress ecosystem vulnerability monitoring (Wordfence). No significant vendor statements, researcher commentary, or broader media coverage beyond standard vulnerability database entries have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."