Executive brief
The Playroom theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code into the website. This could lead to a complete takeover of the site, theft of customer data, or a total service outage. Site owners should update to version 1.5 immediately to prevent potential mass-exploitation campaigns.
Technical details
A PHP Object Injection vulnerability exists in the Playroom theme for WordPress due to the insecure deserialization of user-supplied input (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, SQL injection, or arbitrary file deletion. The vulnerability is patched in version 1.5.
Affected products
- Elated-Themes Playroom <= 1.4.1
Timeline
- 2026-02-12: other: Reported by Denver Jackson
- 2026-04-08: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD