CVE-2026-27096
8.1BuddhaThemes · ColorFolio - Freelance Designer WordPress Theme
The ColorFolio WordPress theme is vulnerable to an object injection attack via deserialization of untrusted data, which may lead to remote code execution.
Executive summary
A deserialization vulnerability in the BuddhaThemes ColorFolio WordPress theme, rated as high severity, poses a significant risk of remote code execution if left unpatched.
Vulnerability
The theme contains an insecure deserialization flaw (CWE-502) that allows an unauthenticated remote attacker to inject malicious objects into the application environment. This vulnerability can be triggered via network-accessible vectors without requiring prior user authentication.
Business impact
The exploitation of this vulnerability could lead to total compromise of the affected WordPress instance, including unauthorized data access, modification, or complete system takeover. With a CVSS score of 8.1, the high potential for impact on confidentiality, integrity, and availability necessitates immediate attention to prevent unauthorized administrative control over the website.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should immediately deactivate or remove the ColorFolio theme until an official security update is released by BuddhaThemes.
Proactive Monitoring: Monitor server access logs for unusual serialized data strings or unexpected POST requests directed at theme-specific endpoints.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules designed to detect and block malicious deserialization attempts or common object injection payloads.
Exploitation status
Public Exploit Available: No confirmed public exploit exists in the available data.
Analyst recommendation
Given the critical nature of object injection vulnerabilities and their potential for full system compromise, the risk should be treated with urgency. Organizations using the BuddhaThemes ColorFolio theme are advised to switch to a secure alternative or disable the theme immediately. Please continue to monitor the Patchstack security database for updates regarding a fix or a patched version from the vendor.
Sources
Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.