Executive brief
Themeton Lagom, a theme for WordPress websites, contains a critical security flaw that allows attackers to inject malicious objects into the system. This vulnerability can be exploited remotely without any user interaction or login credentials. If successful, an attacker could potentially take full control of the website, steal sensitive data, or disrupt services. As the theme has not been updated recently, users are advised to replace it with a supported alternative.
Technical details
A Deserialization of Untrusted Data vulnerability (CWE-502) exists in the Themeton Lagom theme for WordPress through version 2.0. The flaw allows unauthenticated attackers to perform PHP Object Injection by submitting specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, this can lead to arbitrary code execution, SQL injection, or file system traversal. The vulnerability is exploitable over the network without authentication. No official patch is currently available, and the software is considered end-of-life.
Affected products
- Themeton Lagom up to 2.0
Timeline
- 2025-08-05: other: Vulnerability reported by researcher
- 2025-09-04: advisory: Patchstack published advisory details
- 2026-06-17: disclosed: CVE published to NVD