Unauthenticated PHP Object Injection Vulnerability in Law Office Theme by WordPress
CVE-2026-62120
9.8CRITICAL
What is CVE-2026-62120?
The Law Office theme for WordPress, versions 3.20 and below, is susceptible to an unauthenticated PHP Object Injection vulnerability. This flaw allows attackers to exploit the PHP object serialization feature, potentially leading to arbitrary code execution or data manipulation. As no authentication is required to exploit this vulnerability, it poses a significant risk to users of the theme, highlighting the importance of timely updates and security practices.
Affected Version(s)
Law Office <= 3.20