Executive brief
The Château theme for WordPress is vulnerable to a security flaw that allows unauthorized attackers to inject malicious code into a website. This theme is used to control the visual layout and functionality of a site; an exploit could lead to full site takeover, data theft, or the site being used to spread malware. Business operations could be severely impacted through loss of site control and reputation damage.
Technical details
A PHP Object Injection vulnerability exists in the Château theme for WordPress in versions up to and including 1.2.1. The flaw stems from the deserialization of untrusted data (CWE-502), which allows an unauthenticated remote attacker to inject arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or arbitrary file deletion. The attack vector is network-based and requires no user interaction, though the CVSS complexity is rated as high, likely due to the requirement of a usable POP chain. A patch is available in version 1.3.
Affected products
- Mikado-Themes Château <= 1.2.1
Timeline
- 2026-02-24: other: Reported by Denver Jackson
- 2026-04-20: disclosed: Vulnerability published by Patchstack
- 2026-06-17: advisory: NVD published date