CVE-2026-62125: WordPress Asia Garden theme <= 1.3.1 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions.
Affected Software
1 affected component
WordPress Asia Garden<=1.3.1
Event History
Oct 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an attacker to log in or interact with a site user?
No. The vulnerability is unauthenticated, so no attacker account or user interaction is required.
2
Which installations should be prioritized for review?
WordPress sites using the Asia Garden theme at version 1.3.1 or earlier should be treated as affected.