External risk intelligence

ShiftCV Theme Unauthenticated PHP Object Injection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-66564

ShiftCV is a WordPress theme. WordPress themes are commonly used to build public-facing websites and web applications. As a web component intended for public interaction, it is typically deployed in an internet-facing configuration, making the vulnerable surface reachable from the public internet.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in a PHP application, specifically the ShiftCV theme up to version 3.0.14, that allows unauthenticated users to inject malicious code. This could potentially lead to unauthorized access and control over affected systems.

  • Unauthenticated code injection in PHP applications.
  • Critical risk of unauthorized access and control.
  • Confirm relevance and exposure for impacted systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit an unauthenticated PHP object injection vulnerability in the ShiftCV theme to execute arbitrary code. This could happen if the theme is exposed to the internet and receives specially crafted input, allowing the attacker to potentially take control of the affected website.

  • No authentication required.
  • Specially crafted input is sent.
  • Remote code execution on the site.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated PHP Object Injection in ShiftCV could allow an attacker to execute arbitrary code, potentially leading to a complete compromise of the affected website. This could occur when the application deserializes untrusted user-supplied data.

  • Website files and configuration.
  • Via network requests to the application.
  • Complete website compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security and application teams should prioritize identifying all instances of ShiftCV, confirming their exposure and business criticality, and assigning ownership for remediation planning. The first practical step involves locating the affected technology, assessing its reachability and importance, and then engaging the accountable owner to schedule corrective actions based on assessed risk.

  • Application or platform owners.
  • Verify external reachability and business impact.
  • Plan remediation, coordinating with vendor if needed.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ShiftCV theme?

ShiftCV is a WordPress theme designed for building online resumes and personal portfolio websites. It provides the visual layout and structural components for these sites, running on top of the WordPress content management system to handle user-submitted content and display data.

What does PHP object injection mean for CVE-2026-66564?

This vulnerability, classified as CWE-502, involves the insecure deserialization of data. In this context, the theme improperly processes untrusted user-supplied input. By sending a specially crafted object, an attacker can manipulate the application's internal logic, which may lead to the execution of arbitrary code.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending malicious, specially crafted network requests to a site running the affected ShiftCV theme. The vulnerability is specifically tied to the theme's handling of serialized data; it does not trigger if the application is not actively receiving or processing such input from external, untrusted sources.

Is my site at risk if it uses ShiftCV?

If you use ShiftCV, your risk depends on how the site is deployed. According to Halo Surface Signal, this theme is intended for public interaction, meaning it is often configured as an internet-facing component. If your instance is reachable from the public internet, it has a larger attack surface for unauthenticated actors to attempt this exploit.

What should I do if I run this theme?

Your first step is to create an inventory of all websites in your environment that have the ShiftCV theme enabled. Once you have identified these instances, determine if they are internet-facing and assess their business impact. Coordinate with the site owners to plan and schedule necessary updates or security patches to mitigate the risk.

References