Executive brief
The Eldon theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to design and manage the appearance of WordPress websites. If exploited, an attacker could potentially take control of the site, access sensitive data, or cause a complete service outage.
Technical details
A PHP Object Injection vulnerability exists in the Eldon WordPress theme (versions <= 1.4.1) due to the deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component of the theme. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to various high-impact attacks including remote code execution, SQL injection, or arbitrary file deletion. The vulnerability is addressed in version 1.5.
Affected products
- Edge-Themes Eldon <= 1.4.1
Timeline
- 2026-02-12: other: Reported by Denver Jackson
- 2026-04-16: disclosed: Vulnerability published by Patchstack
- 2026-06-17: advisory: CVE published in NVD