External risk intelligence

FC United Theme PHP Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-66565

The vulnerability exists in a WordPress theme, which is a type of web application component. WordPress sites and their themes are commonly deployed as public-facing web services, making the attack surface readily reachable via the internet.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in the FC United WordPress theme, allowing unauthenticated attackers to inject malicious code. This issue could potentially lead to unauthorized access and control over affected systems. The primary concern is to determine if this theme is in use within our environment and, if so, to understand the scope of exposure.

  • Unauthenticated code injection risk.
  • Affects WordPress themes if in use.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to a vulnerable website. This allows them to inject malicious PHP objects, leading to the potential for complete system compromise.

  • No authentication required.
  • Triggered by sending crafted requests.
  • Allows remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject serialized PHP objects into the application, potentially leading to the execution of arbitrary code on the server when the application processes these objects. This could affect the integrity and availability of the web service and any data it manages.

  • Server-side code execution.
  • Via unauthenticated network requests.
  • Compromise of service and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this vulnerability in a WordPress theme, ownership likely falls to the team managing the website and its components, such as the web application or platform team. The first practical step is to identify all instances of the affected theme, assess their exposure and business criticality, and then coordinate remediation with the theme's vendor or development team.

  • Web application team owns the issue.
  • Verify theme presence and public exposure.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the FC United theme?

FC United is a WordPress theme designed to provide visual layouts and structural styling for websites, typically used by sports clubs or organizations. Like other themes, it functions as a collection of PHP files and assets that the WordPress engine interprets to render pages. Because themes often include custom functionality to handle user interactions or data, flaws in their code can impact the security of the entire WordPress installation.

How does PHP object injection work in CVE-2026-66565?

This vulnerability is classified as CWE-502, which involves insecure deserialization. When the theme processes data, it may improperly turn saved strings back into PHP objects. An attacker can supply a specially crafted, malicious object instead of expected data. If the application handles this object, it may trigger unintended code execution or other harmful actions, allowing the attacker to manipulate the application's logic.

Do I need to be logged in for an attacker to trigger this bug?

No, authentication is not required to exploit this issue. An attacker can trigger the vulnerability by sending a malicious network request directly to the vulnerable website. It is important to note that simply visiting the site as a regular user does not trigger the bug; the attacker must specifically send a crafted payload designed to interact with the theme's vulnerable deserialization process.

Is my website at risk from this CVE?

Your risk level depends on whether you have the FC United theme installed and if your site is reachable by others. According to Halo Surface Signal, because this is a WordPress theme, it is frequently used on public-facing web services. If your instance is connected to the internet, it provides an accessible path for an attacker to reach the vulnerable component, increasing the likelihood that it could be targeted.

What should I do first to address this security flaw?

Your first step is to perform an inventory of your WordPress installations to confirm if the FC United theme is currently active. Once identified, evaluate the criticality of those sites and monitor for official updates from the theme's developer. Coordinate with your web application team to plan for updates or temporary mitigation measures to secure the environment while waiting for a vendor-provided fix.

References