External risk intelligence

Stargaze Theme PHP Object Injection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-62051

The vulnerability affects a WordPress theme. WordPress themes are web-based components directly involved in rendering public-facing web pages and processing HTTP requests. Consequently, they are commonly deployed as internet-facing services, making them reachable in typical web server configurations.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns an unauthenticated PHP Object Injection vulnerability found in Stargaze versions up to 1.10. This type of vulnerability can allow unauthorized attackers to execute arbitrary code by manipulating how the application handles serialized data. The primary concern is to confirm if this specific technology is in use and assess potential exposure.

  • Allows unauthenticated code execution.
  • Critical flaw, widely exploitable if used.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to a vulnerable Stargaze installation. This request targets the PHP Object Injection flaw, allowing the attacker to inject malicious PHP objects. If successful, this could lead to the execution of arbitrary code on the server.

  • No authentication required.
  • Triggered by sending a crafted request.
  • Potential for arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated PHP Object Injection in Stargaze could allow an attacker to execute arbitrary code on the server. This is possible when the affected software processes unsanitized user input that can be deserialized, potentially leading to a compromise of the entire system.

  • Server-side code execution.
  • Unauthenticated remote code injection.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated PHP Object Injection vulnerability in Stargaze affects internet-facing web applications. The first practical step is for the web application or platform team to identify all Stargaze installations, determine their reachability and business criticality, and locate the accountable owner. Remediation planning should then be prioritized based on this risk assessment.

  • Application owners should manage remediation.
  • Verify all Stargaze installations.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Stargaze software affected by CVE-2026-62051?

Stargaze is a WordPress theme used to control the visual layout and presentation of websites built on the WordPress platform. Themes like this act as specialized software components that run on the web server, directly interacting with incoming web traffic to display content to visitors.

What does PHP Object Injection mean in this CVE?

This vulnerability involves a weakness known as Insecure Deserialization (CWE-502). It occurs when the theme takes untrusted data and converts it back into a PHP object without proper validation. An attacker can craft this data to force the application to perform unintended actions, effectively tricking the server into executing arbitrary code.

How is this Stargaze vulnerability triggered?

An attacker triggers the flaw by sending a specially crafted HTTP request to a server running the vulnerable theme. The bug is not triggered by standard, benign site navigation or legitimate user interactions; it requires the submission of specifically manipulated serialized data that the theme's code will improperly process.

Do I need to worry about CVE-2026-62051?

Yes, if you manage a WordPress site using this theme. According to Halo Surface Signal, this vulnerability is particularly relevant because Stargaze is a web component that processes HTTP requests and is typically deployed in internet-facing configurations, making it directly reachable to remote attackers without requiring login.

What should I do if I use the Stargaze theme?

Start by identifying every WordPress instance in your environment that has Stargaze installed. Once you have a complete inventory, determine which sites are internet-facing and define their business importance. Use this information to coordinate with the site owners and prioritize the necessary security updates.

References