
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32507 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the Elated-Themes Leroux WordPress theme. It allows unauthenticated remote attackers to perform object injection attacks, potentially enabling code execution, SQL injection, or path traversal if a suitable POP (Property-Oriented Programming) chain exists in the environment. The vulnerability affects all Leroux theme versions prior to 1.4, with version 1.4 being the patched release. It carries a CVSS v3.1 base score of 5.4 (Medium), and was published on March 25, 2026 (Patchstack, Feedly).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), classified under CAPEC-586 (Object Injection). The vulnerability enables PHP Object Injection, where an attacker can supply a crafted serialized PHP object via a network request — no authentication or user interaction is required. Exploitation complexity is rated High, meaning specific conditions or a suitable POP chain within the WordPress installation must be present for full impact. If a POP chain is available, the deserialized object can trigger arbitrary code execution, SQL injection, or path traversal (Patchstack).
Successful exploitation could allow an unauthenticated attacker to inject arbitrary PHP objects, which — when combined with a suitable POP chain present in the WordPress environment — may lead to remote code execution, SQL injection, path traversal, or denial of service. The scope is rated as Changed, meaning the impact can extend beyond the vulnerable component itself to other parts of the WordPress installation or hosted data. Confidentiality and integrity are both rated Low impact in the base score, though real-world impact may be significantly higher depending on available POP chains (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2026-32507 as of the available data. The EPSS score is approximately 0.042%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is unauthenticated and network-accessible, which Patchstack notes makes it a candidate for mass-exploit campaigns targeting WordPress sites at scale. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog based on available information (Patchstack, Feedly).
__wakeup, __destruct, etc.) that form the POP chain.O:, a:, or s: in request parameters or cookies); unexpected outbound connections from the web server process.shell.php, cmd.php).bash, curl, wget); unexpected database queries or file read/write operations logged by security plugins.The vendor (Elated-Themes) has released Leroux version 1.4 as the patched release, which resolves this vulnerability. Site administrators should update the Leroux theme to version 1.4 or later immediately. Patchstack has also issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme can be updated. If an immediate update is not possible, consider temporarily deactivating the theme or consulting your hosting provider (Patchstack).
Patchstack, which discovered and disclosed the vulnerability (credited to researcher Denver Jackson), included it in their weekly WordPress vulnerability report for the week of March 23–29, 2026. Wordfence also covered it in their weekly WordPress vulnerability intelligence report for the same period. No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."