Executive brief
The Nifty theme for WordPress is vulnerable to a critical security flaw that allows unauthorized attackers to inject malicious code into a website. This theme is used to design and manage the appearance of WordPress sites; an exploit could lead to a total takeover of the website, theft of customer data, or a complete service outage. Business owners should update to the latest version immediately to prevent automated attacks.
Technical details
A PHP Object Injection vulnerability exists in the Nifty theme for WordPress (versions <= 1.4.1) due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct arbitrary file deletion. The vulnerability is resolved in version 1.4.2.
Affected products
- BoldThemes (Patchstack) Nifty <= 1.4.1
Timeline
- 2025-10-19: other: Vulnerability reported by researcher Bonds
- 2026-06-12: advisory: Patchstack published advisory
- 2026-06-17: disclosed: CVE published to NVD