CVE-2026-78535: WordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
Affected Software
1 affected component
WordPress Photolia theme<=1.0.3
Event History
Oct 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
Which installations are affected?
WordPress sites using the Photolia theme version 1.0.3 or earlier are affected according to the available information.
3
How severe is the potential impact?
The vulnerability is rated critical with a CVSS score of 9.8. Its vector indicates network-reachable exploitation with low attack complexity and potential high impact to confidentiality, integrity, and availability.