
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32511 is a PHP Object Injection (Deserialization of Untrusted Data) vulnerability in the Mikado-Themes Stål WordPress theme. It allows authenticated attackers with low privileges to perform object injection attacks, potentially enabling code injection, SQL injection, path traversal, or denial of service if a suitable POP (Property-Oriented Programming) chain exists. The vulnerability affects all versions of the Stål theme prior to 1.7, and was published on March 25, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, Feedly).
The root cause is CWE-502 (Deserialization of Untrusted Data), where the Stål theme deserializes user-supplied input without adequate validation, enabling PHP Object Injection (CAPEC-586). An attacker with low-level authenticated access can craft a malicious serialized PHP object and submit it to a vulnerable endpoint within the theme. If a suitable POP chain is available in the WordPress environment (e.g., via installed plugins or PHP libraries), the deserialized object can trigger arbitrary code execution, SQL injection, path traversal, or denial of service. The vulnerability was discovered and reported by Denver Jackson and disclosed by Patchstack on March 23, 2026 (Patchstack).
Successful exploitation can lead to a range of impacts depending on the availability of a POP chain in the target environment, including arbitrary code execution, SQL injection, path traversal, and denial of service. Integrity and availability of the affected WordPress site are at risk (rated Low impact each per CVSS), while confidentiality impact is rated None in the base score. However, in environments with exploitable POP chains, the practical impact could be significantly higher, potentially allowing full site compromise or data exfiltration (Patchstack).
The vulnerability requires low-privilege authentication (no unauthenticated exploitation per CVSS), has low attack complexity, and requires no user interaction. The EPSS score is approximately 0.042% (0.000420), indicating a currently low probability of exploitation in the wild. No public PoC exploit code, active in-the-wild exploitation, or threat actor attribution has been reported at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
/wp-content/themes/stal/), or tools like WPScan./wp-admin/admin-ajax.php) or REST API routes associated with the Stål theme containing serialized PHP data (strings beginning with O:, a:, s:, etc.)./wp-content/themes/stal/) or other writable directories; modification timestamps on core WordPress files that do not align with legitimate updates.bash, curl, wget, python) following suspicious web requests.The primary remediation is to update the Stål WordPress theme to version 1.7 or later, which contains the patch for this vulnerability. Site administrators unable to update immediately should consider using Patchstack's virtual patching (mitigation rule) to block exploitation attempts until the theme can be updated. Additionally, restricting user registration and limiting low-privilege account creation reduces the attack surface, as the vulnerability requires authenticated access (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher Denver Jackson, classified it as medium priority and noted that PHP Object Injection vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the week of March 23–29, 2026 (Wordfence). No significant broader media coverage or notable social media discussion has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."