Sound | Musical Instruments Online Store <= 1.6.9 - Unauthenticated PHP Object Injection
highThe Sound | Musical Instruments Online Store WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.9 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vul...
- CVSS:
- 8.1
- Affected:
- up to 1.6.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025