Executive brief
The Hospital (nrghospital) theme for WordPress is vulnerable to a critical security flaw that allows attackers to inject malicious objects into the application. This theme is used to build and manage hospital or medical-related websites. An exploit could allow an unauthorized user to take complete control of the website, potentially leading to the theft of sensitive data, site defacement, or a total service outage.
Technical details
A PHP Object Injection vulnerability exists in the EMV The Hospital (nrghospital) theme for WordPress due to the deserialization of untrusted data. The flaw allows an unauthenticated remote attacker to supply specially crafted input to a vulnerable component, which is then processed by the PHP unserialize() function. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct arbitrary file manipulation. As of the advisory date, no official patch is available, and users are advised to seek alternative mitigations or themes.
Affected products
- EMV The Hospital (nrghospital) n/a through 1.8.1
Timeline
- 2025-08-05: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2025-09-04: advisory: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date