Executive brief
The Hiroshi theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to design and manage the appearance of WordPress websites. If exploited, an attacker could potentially take full control of the website, access sensitive customer data, or cause a complete service outage.
Technical details
The Hiroshi theme for WordPress (versions <= 1.5.1) is vulnerable to PHP Object Injection via the deserialization of untrusted data (CWE-502). This vulnerability allows an unauthenticated remote attacker to inject PHP objects into the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker can achieve remote code execution, SQL injection, or path traversal. The attack vector is network-based and requires no user interaction, though the CVSS complexity is rated as high. A fix is available in version 1.6.
Affected products
- Select-Themes Hiroshi <= 1.5.1
Timeline
- 2026-02-12: other: Reported by Denver Jackson
- 2026-04-08: disclosed: Published by Patchstack
- 2026-06-17: advisory: NVD published date