CVE-2026-94064: WordPress Neo | Barber Shop WordPress Theme theme <= 3.5 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, and does not require user interaction. An attacker would need an account or another low-privilege access path in the affected WordPress environment.
What versions are affected?
Neo | Barber Shop WordPress Theme is affected through version 3.5. The available data does not identify a fixed version.
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability at a high level. The issue is classified as PHP object injection caused by deserialization of untrusted data.