What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.
Explanation of Vulnerability in Simple Terms
02Summary
The Brooklyn WordPress theme versions up to 4.9.7.6 contain a deserialization vulnerability in how it processes untrusted data. An authenticated attacker with low privileges can exploit this to execute arbitrary code on the site, potentially compromising the entire WordPress installation. The vulnerability requires high attack complexity but grants full control over site data and functionality.
What an attacker can do
03Attacker Capabilities
Run arbitrary code on the site and take full control of the WordPress installation.
Potential impact on your site
04Site Impact
A compromised site can have all data stolen, modified, or deleted; malware injected; or used to attack visitors.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
February 12, 2024
CVE published
April 28, 2026
Record updated