Unauthenticated PHP Object Injection in Buzz Stone Magazine & Viral Blog Theme
CVE-2026-81797
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-81797?
A security vulnerability has been identified in the Buzz Stone Magazine & Viral Blog Theme, specifically affecting versions up to 1.0.2. This flaw enables an unauthenticated attacker to exploit PHP object injection, potentially allowing them to execute arbitrary code within the application's context. This poses a significant risk, as it may lead to unauthorized access to sensitive data and the ability to manipulate the application. Mitigation measures should be implemented promptly for all users of this theme.
Affected Version(s)
Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2