Uxper Togo WordPress Theme Deserialization Vulnerability

Vulnerability

A deserialization vulnerability has been identified in the Uxper Togo WordPress theme, specifically in versions prior to 1.0.4. This vulnerability allows for PHP object injection, which could be exploited to manipulate objects in a way that leads to unintended behavior or security issues.

Impact

Exploitation of this vulnerability could result in PHP object injection, allowing attackers to manipulate object properties and methods, potentially leading to arbitrary code execution or other malicious actions.

Added: Nov 6, 2025, 5:33 PM
Updated: Nov 6, 2025, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.