
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28074 is a PHP Object Injection vulnerability caused by deserialization of untrusted data in the ThemeREX Pizza House WordPress theme. It affects all versions of the Pizza House theme through version 1.4.0 and allows unauthenticated remote attackers to inject malicious PHP objects. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on September 11, 2025, and published by Patchstack on February 27, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). The Pizza House WordPress theme fails to safely handle user-supplied serialized data, allowing an attacker to pass a crafted serialized PHP object that is deserialized server-side without validation. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress environment or installed plugins/themes, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service. No authentication, user interaction, or special privileges are required for exploitation (Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker could execute arbitrary code, perform SQL injection, traverse the file system, exfiltrate sensitive data, or render the site unavailable — depending on the availability of a suitable POP chain in the target environment. The network-accessible, no-authentication-required nature of this vulnerability makes it suitable for mass exploitation campaigns targeting large numbers of WordPress sites (Patchstack).
As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No official patch is available, which increases risk over time. The vulnerability has been noted by Patchstack as high priority and expected to be targeted in mass-exploit campaigns given its unauthenticated, network-accessible attack vector (Patchstack). It does not appear in the CISA KEV catalog at this time.
/wp-content/themes/pizzahouse/style.css).O: prefix in parameters); unexpected outbound connections from the web server to external IPs.unserialize() calls.wp-config.php or .htaccess.bash, curl, wget, python) indicating command execution via deserialization gadget chain.No official patch from ThemeREX is currently available for the Pizza House theme. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until an official fix is released. Site owners should consider disabling or replacing the Pizza House theme immediately if possible, or restricting network access to affected WordPress installations. Monitoring for suspicious activity and contacting ThemeREX directly for an update timeline is also recommended (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability intelligence report for the period of February 23 – March 1, 2026, highlighting it as part of broader WordPress ecosystem risk tracking. Patchstack, the assigning CNA, classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant additional vendor statements or notable researcher commentary beyond these sources have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."