Executive brief
The Moderno theme for WordPress is vulnerable to a critical security flaw that allows unauthorized attackers to take control of a website. By sending a specially crafted request, an attacker can potentially execute malicious code, access sensitive data, or disrupt site operations. This issue affects all versions of the theme prior to 1.43, and site owners should update immediately to prevent compromise.
Technical details
A PHP Object Injection vulnerability exists in the Moderno theme for WordPress in versions prior to 1.43. The flaw stems from the deserialization of untrusted data (CWE-502) without proper validation. An unauthenticated remote attacker can exploit this by submitting a malicious payload that, when processed by the server, can leverage available 'Property Oriented Programming' (POP) chains to achieve remote code execution, SQL injection, or file system access. The vulnerability is exploitable over the network without user interaction. Users are advised to upgrade to version 1.43 or later to mitigate the risk.
Affected products
- park_of_ideas Moderno < 1.43
Timeline
- 2026-01-07: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
- 2026-06-04: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date