Executive brief
The Manufaktur Solutions theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to design and manage the appearance of WordPress websites. If exploited, an attacker could potentially take control of the website, access sensitive data, or disrupt services without needing any login credentials.
Technical details
A PHP Object Injection vulnerability exists in the Manufaktur Solutions theme for WordPress in versions up to and including 1.1.1. The flaw stems from the deserialization of untrusted data (CWE-502), which allows an unauthenticated attacker to inject malicious PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or path traversal. The attack can be launched over the network without user interaction, though the CVSS vector indicates high complexity (AC:H). The vulnerability is resolved in version 1.2.
Affected products
- Select-Themes Manufaktur Solutions <= 1.1.1
Timeline
- 2026-02-24: other: Reported by Denver Jackson
- 2026-04-20: disclosed: Vulnerability published by Patchstack
- 2026-06-17: advisory: CVE published in NVD