Junglewise Threat Intelligence

CVE-2026-27414: Fuelthemes Werkstatt PHP object injection

CVE-2026-27414 · Severity: high · CVSS 8.8 · Published 2026-07-02

Technologies: Fuelthemes Werkstatt. Vendors: Fuelthemes.

Executive brief

The Werkstatt theme for WordPress is vulnerable to a security flaw that could allow an attacker with basic contributor-level access to compromise the website. By exploiting this issue, a malicious user could potentially take control of the server, access sensitive data, or disrupt site operations. As of the latest report, there is no official patch available from the developer, so site administrators should consider alternative security mitigations.

Technical details

The Werkstatt theme for WordPress (versions up to and including 4.8.3) is vulnerable to PHP Object Injection due to the deserialization of untrusted data (CWE-502). An attacker with Contributor-level privileges can exploit this vulnerability to inject PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or path traversal. The attack is reachable over the network and does not require user interaction, though it does require valid low-level authentication. No official patch has been released by the vendor at the time of reporting.

Affected products

  • Fuelthemes Werkstatt <= 4.8.3

Timeline

  • 2025-10-31: other: Vulnerability reported by researcher
  • 2026-06-30: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: CVE published to NVD

References

Related threats