CVE-2026-94065: WordPress ColorFolio theme <= 1.3 - PHP Object Injection vulnerability
Published Oct 9, 2026
·Updated
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.
Affected Software
1 affected component
BuddhaThemes ColorFolio<=1.3
Event History
Oct 9, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, and does not require user interaction. An attacker would need an account or other access level corresponding to low privileges.
2
Which installations are affected?
ColorFolio versions through 1.3 are affected. The available information does not identify a fixed version.
3
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability at a high level, according to the reported CVSS metrics.