Executive brief
The Töbel theme for WordPress is vulnerable to a security flaw that could allow an attacker to take control of a website. By sending specially crafted data to the site, an attacker could potentially execute malicious code or access sensitive information. This issue affects websites using version 1.8.1 or earlier of the theme, and administrators should update to version 1.9 immediately to protect their operations and data.
Technical details
A PHP Object Injection vulnerability exists in the Elated-Themes Töbel theme (versions up to 1.8.1) due to the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by submitting malicious input that the application passes to a PHP unserialize() function. If a suitable Property-Oriented Programming (POP) chain is present within the environment, this can lead to various high-impact attacks including remote code execution, SQL injection, or arbitrary file deletion. The vulnerability is mitigated in version 1.9.
Affected products
- Elated-Themes Töbel <= 1.8.1
Timeline
- 2026-02-12: other: Vulnerability reported by Denver Jackson
- 2026-04-08: disclosed: Initial disclosure by Patchstack
- 2026-06-02: advisory: NVD publication date