Junglewise Threat Intelligence

CVE-2026-57738: AxiomThemes 777 PHP object injection

CVE-2026-57738 · Severity: critical · CVSS 9.8 · Published 2026-07-13

Vendors: Axiomthemes.

Executive brief

AxiomThemes 777 (triple-seven) is a WordPress theme used for building websites. A critical security flaw allows unauthenticated attackers to inject malicious code into the website. If exploited, this could lead to a complete takeover of the site, theft of customer data, or a total service outage.

Technical details

The AxiomThemes 777 (triple-seven) theme for WordPress contains a PHP Object Injection vulnerability due to the deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable component that uses the PHP unserialize() function. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker could achieve remote code execution, SQL injection, or arbitrary file access. As of the advisory date, no official patch is available from the vendor, and users are advised to use third-party mitigation rules.

Affected products

  • AxiomThemes 777 (triple-seven) <= 1.13.0

Timeline

  • 2026-02-28: disclosed: Reported by Bonds to Patchstack
  • 2026-07-09: advisory: Patchstack published advisory and mitigation rules
  • 2026-07-13: advisory: CVE published to NVD dataset

References