Executive brief
The Fidalgo theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to inject malicious code into the website. This type of vulnerability is often used in large-scale automated attacks to take over websites, steal sensitive data, or disrupt services. Site owners should update to version 1.3 immediately to protect their operations and reputation.
Technical details
A PHP Object Injection vulnerability (CWE-502) exists in the Elated-Themes Fidalgo theme for WordPress in versions up to and including 1.2.2. The flaw stems from the deserialization of untrusted data, which allows an unauthenticated remote attacker to inject arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can be leveraged to achieve remote code execution, SQL injection, or file system traversal. The attack requires no user interaction or privileges, though the CVSS vector indicates high complexity (AC:H). A patch is available in version 1.3.
Affected products
- Elated-Themes Fidalgo <= 1.2.2
Timeline
- 2026-02-12: other: Reported by Denver Jackson
- 2026-04-08: disclosed: Vulnerability details published by Patchstack
- 2026-06-17: advisory: NVD advisory published