Executive brief
The Esmée theme for WordPress is vulnerable to a security flaw that allows unauthorized users to inject malicious code. This theme is used to customize the appearance and functionality of WordPress websites. If exploited, an attacker could potentially take over the website, steal sensitive data, or cause a total service outage.
Technical details
A PHP Object Injection vulnerability (CWE-502) exists in the Esmée WordPress theme versions up to and including 1.4. The flaw stems from the deserialization of untrusted data, which allows an unauthenticated attacker to inject PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or arbitrary file deletion. The attack can be performed over the network without any user interaction, though the complexity is rated as high. Users are advised to update to version 1.5 or later to remediate the issue.
Affected products
- Mikado-Themes Esmée <= 1.4
Timeline
- 2026-02-24: other: Reported by Denver Jackson
- 2026-04-20: disclosed: Vulnerability published by Patchstack
- 2026-06-17: advisory: CVE published in NVD