Executive brief
The Creatify theme for WordPress is vulnerable to a critical security flaw that allows attackers to inject malicious code into a website. This could lead to full site takeover, data theft, or the deletion of website files. Because there is currently no official patch and the theme has not been updated recently, it is recommended to replace the theme entirely to protect your operations.
Technical details
A PHP Object Injection vulnerability exists in the EMV Creatify theme (versions 1.5 and below) due to the unsafe deserialization of user-supplied input. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, this can lead to arbitrary code execution, SQL injection, or file system manipulation. As of the advisory date, no official patch is available, and the software is considered end-of-life.
Affected products
- EMV Creatify <= 1.5
Timeline
- 2025-07-31: other: Vulnerability reported by researcher
- 2025-08-30: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: CVE published to NVD