External risk intelligence

Splendour Theme PHP Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-62050

The vulnerability affects a WordPress theme, which is a component of a web application. WordPress sites are frequently deployed as public-facing web services, making the theme's code reachable over the internet in common deployment patterns.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns an unauthenticated PHP Object Injection vulnerability in a widely used website technology that could allow unauthorized access and manipulation of systems. The primary concern is to confirm if our organization utilizes the affected technology and assess potential exposure.

  • Code flaw lets unauthenticated users inject code.
  • Critical flaw bypasses authentication and control.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this PHP Object Injection vulnerability by sending a specially crafted request to a website using the affected theme. This could lead to the execution of arbitrary code, compromise of data, and full control over the website.

  • No authentication required.
  • Triggered by a crafted request.
  • Results in code execution and site takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject serialized PHP objects into the system. When these objects are later unserialized, it could lead to arbitrary code execution, potentially impacting the integrity and availability of the affected application. This could occur when the application processes user-supplied input that is not properly sanitized before being passed to PHP's unserialization functions, and when supported by the advisory, could affect the entire system.

  • System integrity and availability.
  • Processing unsanitized user input.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Unauthenticated PHP Object Injection in Splendour versions prior to and including 1.23 impacts web applications, placing responsibility on application owners and potentially infrastructure or security teams to manage risk. The first crucial step is to identify all instances of Splendour, determine their exposure and criticality, and then assign ownership for remediation.

  • Application owners should manage this.
  • Verify Splendour usage and exposure.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Splendour theme?

Splendour is a theme used within the WordPress content management system. Themes define the visual design and layout of a website. Because they often include custom functionality to handle dynamic content, they become part of the application code that executes on the server whenever a user visits the site.

What does CVE-2026-62050 mean by PHP Object Injection?

This is a weakness known as CWE-502, Deserialization of Untrusted Data. It occurs when a program takes user-provided data and converts it back into an object without proper validation. An attacker can craft a specific, malicious object that, once processed, tricks the application into performing unintended actions or running unauthorized code.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specially crafted network request containing malicious serialized data to the web server. It is important to note that simply visiting the site or browsing normal pages does not trigger the bug; the system must specifically receive and process an improperly handled payload designed to exploit the unserialization process.

Do I need to worry about this if my site is not public?

Halo Surface Signal indicates this vulnerability is classified as external because WordPress themes are commonly deployed as public-facing services. While internet-facing sites are at the highest risk, any environment where the theme is accessible via a network could potentially be targeted if an attacker gains entry to that network segment.

When should I take action for Splendour?

You should act immediately by locating all installations of the Splendour theme within your infrastructure. Once identified, verify if you are running version 1.23 or earlier. If you are, prioritize confirming ownership of those specific sites and prepare to apply updates or implement protective controls to mitigate the risk of unauthorized system access.

References