Executive brief
The Kapee theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to build and design e-commerce websites. If exploited, an attacker could potentially take full control of the website, steal customer data, or disrupt business operations.
Technical details
A PHP Object Injection vulnerability exists in the Kapee theme for WordPress in versions prior to 1.7.0. The flaw stems from the deserialization of untrusted data (CWE-502), which can be triggered by an unauthenticated remote attacker. If a suitable Property-Oriented Programming (POP) chain is present within the environment, an attacker can leverage this to execute arbitrary code, perform SQL injection, or achieve path traversal. The attack complexity is rated as high, likely due to the requirement of a specific POP chain to achieve full remote code execution. Users are advised to update to version 1.7.0 or later.
Affected products
- PressLayouts Kapee < 1.7.0
Timeline
- 2026-02-12: other: Vulnerability reported by researcher Phat RiO
- 2026-04-22: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published to NVD