Junglewise Threat Intelligence

CVE-2026-42380: jwsthemes AI Lab PHP Object Injection

CVE-2026-42380 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Executive brief

AI Lab is a WordPress theme used for building websites. A critical security flaw allows unauthenticated attackers to inject malicious code into the server. This could lead to a complete takeover of the website, theft of sensitive data, or a total service outage. Owners of websites using this theme should update to version 5.4.2 immediately to prevent automated attacks.

Technical details

A PHP Object Injection vulnerability exists in the AI Lab theme for WordPress due to improper deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker can achieve remote code execution, perform SQL injection, or access sensitive files via path traversal. The vulnerability is resolved in version 5.4.2.

Affected products

  • jwsthemes AI Lab < 5.4.2

Timeline

  • 2026-03-02: other: Vulnerability reported by Tran Nguyen Bao Khanh
  • 2026-04-27: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References