Executive brief
The Askka theme for WordPress contains a security flaw that allows attackers to inject malicious data into the website's processing engine. If exploited, this could allow an unauthorized person to take control of the site, access sensitive data, or disrupt services. This type of vulnerability is often targeted in automated mass-attacks against WordPress websites.
Technical details
A PHP Object Injection vulnerability exists in the Elated-Themes Askka theme through version 1.3.1 due to the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component. If a suitable Property-Oriented Programming (POP) chain is present within the environment, this can lead to various high-impact outcomes including arbitrary code execution, SQL injection, or file system traversal. The vulnerability is mitigated in version 1.4.
Affected products
- Elated-Themes Askka <= 1.3.1
Timeline
- 2026-02-12: other: Vulnerability reported by Denver Jackson
- 2026-04-08: advisory: Patchstack published advisory
- 2026-06-02: disclosed: CVE published to NVD
- 2026-04-08: patched: Version 1.4 released to address the issue