Executive brief
Micdrop, a professional WordPress theme, contains a security flaw that allows unauthorized users to inject malicious data into the website's processing engine. If exploited, an attacker could potentially take full control of the website, steal sensitive customer data, or disrupt services. This vulnerability is particularly dangerous because it does not require a login to exploit.
Technical details
A PHP Object Injection vulnerability exists in the Micdrop theme for WordPress due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is present in versions up to and including 1.3.1 and has been addressed in version 1.4.
Affected products
- Select-Themes Micdrop <= 1.3.1
Timeline
- 2026-02-13: other: Reported by Denver Jackson
- 2026-04-08: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date