Executive brief
The Valiance theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious code into the website. This could lead to full site takeover, data theft, or service disruption. Website owners should update to version 1.3 immediately to protect their operations and customer data.
Technical details
A PHP Object Injection vulnerability exists in the Valiance theme for WordPress (versions <= 1.2) due to improper deserialization of untrusted data. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, arbitrary file deletion, or sensitive data exposure. The issue is resolved in version 1.3.
Affected products
- Elated-Themes Valiance <= 1.2
Timeline
- 2026-02-12: other: Reported by Denver Jackson
- 2026-04-08: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD