Executive brief
EasyMeals is a WordPress theme designed for food and recipe websites. A security flaw in versions 1.5.1 and earlier allows an unauthenticated attacker to inject malicious code into the website. If successfully exploited, this could lead to full site takeover, data theft, or the deletion of website files, potentially disrupting business operations and damaging the site's reputation.
Technical details
A PHP Object Injection vulnerability exists in the EasyMeals WordPress theme due to the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component of the theme. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker could achieve remote code execution, perform SQL injection, or conduct arbitrary file operations. The vulnerability is patched in version 1.6.
Affected products
- Mikado-Themes EasyMeals <= 1.5.1
Timeline
- 2026-02-24: other: Reported by Denver Jackson
- 2026-04-20: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date