CVE-2026-27096: WordPress ColorFolio - Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrusted data vulnerability
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through 1.3.
Other sources
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme colorfolio allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through <= 1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27096?
CVE-2026-27096 is classified as a high-severity vulnerability due to its potential for object injection attacks.
How do I fix CVE-2026-27096?
To fix CVE-2026-27096, update your BuddhaThemes ColorFolio - Freelance Designer WordPress Theme to version 1.4 or later.
What type of vulnerability is CVE-2026-27096?
CVE-2026-27096 is a deserialization of untrusted data vulnerability which allows for object injection.
Who is affected by CVE-2026-27096?
Users of BuddhaThemes ColorFolio - Freelance Designer WordPress Theme versions 1.3 and below are affected by CVE-2026-27096.
What are the potential impacts of CVE-2026-27096?
The potential impacts of CVE-2026-27096 include unauthorized access and manipulation of server-side objects.