External risk intelligence

Law Office Theme PHP Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-62120

The vulnerability affects a WordPress theme. WordPress themes are public-facing components of web applications by design, making the web server hosting the site directly reachable from the internet.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified that affects the Law Office software. This issue could allow unauthorized access to systems and data due to a flaw in how the software handles specific data inputs. The primary concern at this time is to determine if our organization utilizes this software and, if so, to what extent it may be exposed.

  • Unauthenticated code injection in Law Office software.
  • Critical flaw impacts public-facing website components.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to a vulnerable installation of the Law Office theme. This request targets a feature that is susceptible to PHP Object Injection, potentially allowing the attacker to execute arbitrary code on the server.

  • No authentication required.
  • Triggers PHP Object Injection.
  • Leads to code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject malicious PHP objects into the Law Office application. This could potentially lead to the execution of arbitrary code or the manipulation of application data when supported by the advisory.

  • Sensitive application data could be exposed.
  • Malicious code injection via unauthenticated requests.
  • Compromise of application integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated PHP Object Injection vulnerability in Law Office affects public-facing websites, making initial triage critical. Infrastructure or platform teams should be engaged to identify all instances of the affected theme and confirm their network exposure. Subsequently, application owners or vendor management should coordinate remediation efforts, prioritizing business-critical or externally facing systems.

  • Identify and confirm affected theme instances.
  • Verify external reachability and business criticality.
  • Coordinate vendor engagement for remediation planning.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Law Office software?

Law Office is a WordPress theme designed to help legal professionals and law firms create professional-looking websites. As a theme, it controls the visual design and structural layout of a site, and it is built to run within the WordPress content management system.

What does PHP Object Injection mean for CVE-2026-62120?

This vulnerability is classified as CWE-502. It means the software insecurely processes user-supplied data during deserialization. By sending specially crafted input, an attacker can trick the application into creating unexpected objects, which can lead to unauthorized code execution or system compromise.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a malicious network request to a site running a vulnerable version of the Law Office theme. Because it is an unauthenticated vulnerability, no login or special user privileges are required. Standard, legitimate site traffic that does not contain these specific, crafted objects will not trigger the bug.

Is my site at risk according to Halo Surface Signal?

Yes, it is highly relevant if you use this theme. Halo Surface Signal identifies this as a public-facing component. Since WordPress themes are designed to be reached by users over the internet, a server hosting an affected Law Office site is directly exposed to external, unauthorized access attempts.

Do I need to take action to secure my installation?

Yes, you should immediately inventory your web environments to locate all instances where the Law Office theme is active. Once identified, work with your infrastructure or application teams to assess the risk and coordinate the necessary vendor updates to patch the vulnerability and protect your server integrity.

References