ColorFolio - Freelance Designer WordPress <= 1.3 - Authenticated (Subscriber+) PHP Object Injection
highThe ColorFolio - Freelance Designer WordPress theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known P...
- CVSS:
- 7.5
- Affected:
- up to 1.3
- Fix:
- No patched version reported
- Disclosed:
- Aug 4, 2026