Sceawere
Vulnerability Detail
CVE-2026-96831UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Themify Builder PHP Object Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- themifyme
- Product
- Themify Builder
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-30T13:17:32.893Z",
"pubdate": "2026-09-30T13:17:32.893Z",
"executiveSummary": "A critical PHP Object Injection vulnerability exists in Themify Builder versions 7.8.1 and below. The flaw originates from improper handling of user-supplied serialized data, allowing authenticated attackers with contributor-level privileges to manipulate serialized objects.\nBy injecting malicious serialized payloads, an attacker can influence the application's runtime environment, potentially leading to arbitrary code execution, unauthorized file system access, or sensitive data exposure depending on the available gadget chains within the application's scope.\nThis vulnerability is particularly dangerous as it bypasses standard input sanitization by leveraging PHP's native deserialization mechanisms. The exploit requires authentication as a user with at least Contributor-level access, meaning an attacker must already have a foothold in the WordPress ecosystem.\nSuccessful exploitation compromises the integrity and confidentiality of the WordPress instance and the underlying server. Immediate remediation via version updates is required to neutralize the injection vector.",
"technicalDetails": "The vulnerability manifests within the Themify Builder plugin due to the insecure deserialization of untrusted input. In PHP, the unserialize() function processes string representations of objects, restoring them to their original state. If the input is not validated, an attacker can supply a specially crafted string that represents an object of a class present in the application's codebase.\nWhen the application deserializes this input, it triggers the instantiation of the object. If the application environment contains 'gadget chains'—specifically, classes that define magic methods like __destruct(), __wakeup(), or __toString()—an attacker can chain these method calls to execute arbitrary code or perform unauthorized actions when the object is instantiated or destroyed.\nThe attack flow initiates when a Contributor-level user sends a crafted request to the Themify Builder API or form handlers that process serialized data. Because the application fails to implement adequate input validation or integrity checks (such as HMAC signing) on the serialized string, the PHP engine processes the malicious object blindly.\nBy manipulating the properties of these gadgets, an attacker can achieve Remote Code Execution (RCE) by leveraging classes that perform file operations or database queries using properties controlled by the attacker. Since the plugin is integrated into the WordPress environment, the attacker can leverage existing WordPress core functions or other installed plugin classes to extend the impact of the object injection.\nThis vulnerability is classified as an Authenticated PHP Object Injection. The exploitation is restricted to the network-accessible interface of the Themify Builder. While the vulnerability requires Contributor privileges, the impact on the server is severe, as the PHP process inherits the permissions of the web server user. Once the object is injected, the post-exploitation impact includes the potential for full server compromise, persistent backdoor placement, or data exfiltration from the WordPress database."
}