SECURITYHIGHCVE-2026-104747

CVE-2026-104747: Unauthenticated PHP Object Injection in the Haaken WordPress Theme

The Haaken WordPress theme (≤ 1.5) allows unauthenticated PHP object injection via insecure deserialization, rated CVSS 8.1.

Dylan H.

Security Team

October 7, 2026
5 min read
CVE-2026-104747: Unauthenticated PHP Object Injection in the Haaken WordPress Theme

Affected Products

  • Haaken WordPress theme (Edge-Themes) 1.5 and earlier

Overview

A high-severity vulnerability has been disclosed in Haaken, a commercial WordPress theme published by Edge-Themes. Tracked as CVE-2026-104747 with a CVSS score of 8.1, the flaw allows an unauthenticated attacker to trigger PHP Object Injection through insecure deserialization of untrusted input, affecting all versions up to and including 1.5.

PHP Object Injection vulnerabilities are especially dangerous because they don't require a direct code-execution primitive to be dangerous on their own — if the vulnerable application or any installed plugin ships a class with an exploitable "magic method" (__wakeup(), __destruct(), __toString(), and similar), an attacker can chain it into a gadget chain leading to remote code execution, arbitrary file writes, or full site compromise.


Technical Details

FieldValue
CVE IDCVE-2026-104747
SeverityHigh (CVSS 8.1)
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-502 — Deserialization of Untrusted Data
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
User InteractionNone
Affected VersionsHaaken theme 1.5 and earlier
Fixed VersionNot yet published at time of writing — see Mitigation

How It Works

The Haaken theme deserializes attacker-supplied input somewhere in its codebase without first validating or restricting the classes that can be instantiated. Because PHP's unserialize() function will happily reconstruct arbitrary objects from a crafted string, an attacker who can reach the vulnerable code path — without needing to log in first — can submit a specially-built serialized payload.

On its own, object injection just creates an unexpected object. The real danger comes from gadget chains: if any class loaded by WordPress core, an active plugin, or the theme itself implements a magic method that performs a dangerous action (deleting files, writing to the filesystem, making HTTP requests, or executing code) when the object is instantiated or destroyed, the attacker can use that class as the "gadget" to escalate the injection into real impact. The CVSS vector's AC:H (high attack complexity) reflects the fact that building a working gadget chain generally requires the attacker to first identify a usable gadget in the site's installed plugin/theme stack — but once one exists, exploitation is unauthenticated and requires no user interaction.


Impact Assessment

Who Is At Risk

Any WordPress site running the Haaken theme in a version at or below 1.5 is affected. Because object injection severity depends heavily on what other code is loaded alongside the vulnerable component, actual impact varies by site:

  • Sites running Haaken alongside plugins known to contain exploitable gadget chains face the highest risk — potentially full remote code execution
  • Sites without an obvious gadget chain are still exposed to confidentiality and integrity impacts (the CVSS vector rates C:H/I:H/A:H — high impact across all three)
  • Multi-site and agency deployments that reuse the same theme/plugin combination across many client sites multiply the blast radius of a single discovered gadget chain

Potential Attack Chain

  1. Reconnaissance — Attacker fingerprints the target as running the Haaken theme (via theme assets, headers, or wp-content/themes/haaken/)
  2. Gadget Discovery — Attacker enumerates classes available in WordPress core and any installed plugins to find a usable magic-method gadget
  3. Payload Delivery — Attacker submits a crafted serialized PHP object to the vulnerable deserialization sink, unauthenticated
  4. Exploitation — The deserialization process instantiates the attacker's object, triggering the gadget's magic method and whatever downstream action it performs

Mitigation

Immediate Actions

  • Check for a vendor update to Haaken beyond version 1.5 and apply it as soon as it is available — no patched version was listed publicly at time of writing
  • If no patch is available, consider temporarily disabling or replacing the theme on internet-facing sites, particularly those running plugins with a history of object-injection gadgets
  • Run a WordPress-aware vulnerability scanner (e.g., WPScan, Patchstack) against affected sites to confirm exposure and check for known gadget chains in your installed plugin set

Detection Opportunities

  • Review web server and WAF logs for unusually long, PHP-serialization-formatted request parameters (strings beginning with patterns like O:, a:, or s: followed by digits)
  • Monitor for unexpected file writes, outbound requests, or process spawns correlating with requests to theme-handled endpoints
  • A web application firewall rule blocking PHP serialization payloads in untrusted input fields is a reasonable stopgap while awaiting a vendor fix

Defence-in-Depth

  • Keep the overall plugin and theme inventory on affected sites as lean as possible — every additional active class is a potential gadget
  • Disable PHP's unserialize() where the application logic allows it, in favor of safer formats like JSON
  • Apply the principle of least privilege to the web server's file-system and database permissions to limit the damage a successful gadget chain can do

Discovery & Disclosure

CVE-2026-104747 was published on October 6, 2026, with the advisory originating from Patchstack's WordPress vulnerability database. As of publication, it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and EPSS scoring places the 30-day exploitation probability at a low 0.26%. No public proof-of-concept gadget chain has been confirmed, but given the unauthenticated, zero-interaction attack surface, sites running the Haaken theme should prioritize confirming their exposure rather than waiting for in-the-wild exploitation to be observed.


References