WordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerability
Description
Unauthenticated PHP Object Injection in SeaFood Company WordPress theme <=1.4 allows remote code execution via crafted serialized input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated PHP Object Injection in SeaFood Company WordPress theme <=1.4 allows remote code execution via crafted serialized input.
Vulnerability
The SeaFood Company WordPress theme versions 1.4 and earlier are vulnerable to unauthenticated PHP Object Injection. The vulnerability exists in the theme's handling of user-supplied input that is deserialized without proper validation. No authentication or special configuration is required to reach the vulnerable code path. [1]
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request containing a malicious serialized PHP object to the affected theme endpoint. No prior authentication or user interaction is needed. The attacker only requires network access to the target WordPress site. [1]
Impact
Successful exploitation can lead to arbitrary code execution, SQL injection, path traversal, or denial of service if a suitable POP (Property Oriented Programming) chain is present in the environment. The CVSS score is 9.8, indicating critical severity. This vulnerability is expected to be used in mass-exploit campaigns. [1]
Mitigation
Users should update the SeaFood Company theme to the latest available version immediately. If no patched version is yet available, consider disabling the theme or implementing a web application firewall rule to block malicious serialized payloads. Contact your hosting provider for assistance if needed. [1]
AI Insight generated on Jun 17, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (May 25, 2026 to May 31, 2026)Wordfence Blog · Jun 4, 2026