Executive brief
FreightCo is a WordPress theme used by websites to display content and manage site presentation. An unauthenticated attacker can inject malicious PHP objects into the theme, allowing them to execute arbitrary code on the website server. This could lead to complete server compromise, data theft, website defacement, or deployment of malware.
Technical details
This vulnerability is a PHP object injection (deserialization) flaw in FreightCo theme versions 1.1.15 and earlier. The vulnerability is unauthenticated, meaning no login credentials are required to exploit it. An attacker can manipulate serialized PHP objects to trigger unintended code execution on the server. The attack vector is network-based and requires no user interaction. Successful exploitation allows arbitrary code execution with the privileges of the web server process. No official patch is currently available according to the advisory.
Affected products
- FreightCo FreightCo <= 1.1.15
Timeline
- 2026-08-20: disclosed
- 2026-08-24: advisory