Executive brief
The ShiftUp theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to inject malicious code into a website. ShiftUp is a visual theme used to design and display WordPress sites. If exploited, an attacker could potentially take full control of the website, steal sensitive customer data, or cause the site to become unavailable, leading to significant operational and reputational damage.
Technical details
The ShiftUp theme for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.3. This vulnerability occurs due to the deserialization of untrusted data (CWE-502) without proper validation. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is addressed in version 1.4.
Affected products
- Mikado-Themes ShiftUp <= 1.3
Timeline
- 2026-02-11: other: Reported by Denver Jackson
- 2026-04-16: disclosed: Vulnerability details published by Patchstack
- 2026-06-17: advisory: CVE published to NVD