PT-2026-109589 · Axiomthemes · Balance
CVE-2026-93945
·
Published
2026-10-10
·
Updated
2026-10-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Axiomthemes Balance versions prior to 1.12.1
Description
The Axiomthemes Balance WordPress theme contains a flaw where it deserializes untrusted user-controlled data using the
unserialize() function. This allows for PHP object injection, where remote attackers can use crafted serialized payloads to trigger gadget chains, potentially leading to remote code execution, unauthorized file writes, or full site takeover.Recommendations
Update Axiomthemes Balance to a version newer than 1.12.0.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Balance