
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32510 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the Edge-Themes Kamperen WordPress theme. It affects all versions of the Kamperen theme prior to 1.3 and was published on March 25, 2026, with the initial report submitted by researcher Denver Jackson on January 20, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, Feedly).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), enabling PHP Object Injection (CAPEC-586). When the Kamperen theme deserializes user-supplied data without proper validation, an attacker can craft a malicious serialized PHP object that the application instantiates. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve code injection, SQL injection, path traversal, or denial of service. The attack vector is network-based, requires low privileges, and no user interaction (Patchstack).
Successful exploitation of this vulnerability can lead to a range of consequences depending on the availability of a POP chain in the target environment, including arbitrary code execution, SQL injection, path traversal, and denial of service. Integrity and availability impacts are rated as low in isolation, but the presence of a suitable POP chain could significantly escalate the severity, potentially allowing full site compromise, data exfiltration, or persistent backdoor installation. Confidentiality impact is rated as none in the base score, though chained exploitation could expose sensitive data (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2026-32510 at this time. The EPSS score is approximately 0.024% (0.000240), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack, Wordfence).
/wp-content/themes/kamperen/style.css).O: or a:) to theme-related endpoints; unexpected outbound connections from the web server process.unserialize() calls.shell.php, cmd.php) or unexpected changes to theme files.bash, curl, wget, python) that are not typical for normal WordPress operation.The vendor has released version 1.3 of the Kamperen theme, which patches this vulnerability. Site administrators should update the Kamperen theme to version 1.3 or later immediately. Patchstack has also issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until the theme is updated. If an immediate update is not possible, consider temporarily deactivating the theme or consulting your hosting provider (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the week of March 23–29, 2026, highlighting it as part of a broader set of WordPress theme and plugin vulnerabilities disclosed that week (Wordfence). Patchstack, the assigning CNA, emphasized that PHP Object Injection vulnerabilities of this class are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack). No significant broader media coverage or notable researcher commentary beyond these sources has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."