Executive brief
The Roisin theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code into a website. This could lead to a total takeover of the site, theft of customer data, or a complete service outage. Website owners using this theme should update to version 1.5 immediately to protect their operations and reputation.
Technical details
A PHP Object Injection vulnerability exists in the Roisin theme for WordPress in versions up to and including 1.4. The flaw stems from the deserialization of untrusted data (CWE-502) without proper validation. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker could achieve remote code execution, perform SQL injection, or access sensitive files. The vulnerability is addressed in version 1.5.
Affected products
- Elated-Themes Roisin <= 1.4
Timeline
- 2026-02-24: other: Reported by Denver Jackson
- 2026-04-20: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date