
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27439 is a Deserialization of Untrusted Data vulnerability (PHP Object Injection) in the ThemeREX Dentario WordPress theme, affecting all versions through 1.5. It allows unauthenticated remote attackers to inject malicious PHP objects without any user interaction. The vulnerability was published on March 5, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Patchstack).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which enables PHP Object Injection (CAPEC-586). When the Dentario theme deserializes attacker-controlled input without validation, a malicious actor can craft a serialized PHP object payload that, upon deserialization, triggers arbitrary code execution via PHP magic methods (e.g., __wakeup, __destruct). No authentication or user interaction is required, and attack complexity is low, making this trivially exploitable over the network (Feedly, Patchstack).
Successful exploitation grants an unauthenticated attacker full control over the affected WordPress installation, with high impact to confidentiality, integrity, and availability. An attacker can achieve remote code execution, enabling them to read or exfiltrate sensitive data (e.g., database credentials, user PII), modify or delete site content, install backdoors, and potentially pivot to the underlying server or hosting environment (Feedly).
As of the time of reporting, no public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Feedly, Patchstack).
__wakeup or __destruct.O:, a:, s:) in parameters or cookies targeting the Dentario theme endpoints; unexpected outbound connections from the web server to external IPs.wp-config.php or core WordPress files.bash, curl, wget, python) indicating command execution following deserialization.No patch has been confirmed available for the ThemeREX Dentario theme as of the disclosure date; users should monitor ThemeREX and Patchstack for an updated version exceeding 1.5 and apply it immediately when released. As interim mitigations, consider deactivating and removing the Dentario theme if it is not essential, or deploying a Web Application Firewall (WAF) with rules to detect and block serialized PHP object payloads. Additionally, restrict access to the WordPress admin panel, enforce the principle of least privilege on the web server, and consider replacing PHP serialization with safer data formats (e.g., JSON) where feasible (Feedly, Patchstack).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report covering the period of February 23 – March 1, 2026, highlighting it among other WordPress theme and plugin issues. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."