CVE-2026-32506
Received Received - Intake
Deserialization Vulnerability in Archicon Edge-Themes Enables Object Injection

Publication date: 2026-03-25

Last updated on: 2026-04-29

Assigner: Patchstack

Description
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-25
Last Modified
2026-04-29
Generated
2026-06-16
AI Q&A
2026-03-25
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
edge-themes archicon to 1.7 (exc)
patchstack archicon to 1.7 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a Deserialization of Untrusted Data issue in the Edge-Themes Archicon plugin. It allows an attacker to perform Object Injection by exploiting the way Archicon handles deserialization of data. This affects versions of Archicon up to, but not including, version 1.7.

Impact Analysis

The vulnerability can allow an attacker to inject malicious objects during the deserialization process, potentially leading to unauthorized code execution, data manipulation, or other malicious actions within the affected application.

Compliance Impact

The provided information does not specify how the CVE-2026-32506 vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.

Detection Guidance

This vulnerability affects WordPress sites using the Archicon Theme versions prior to 1.7 and involves PHP Object Injection. Detection typically involves identifying if the vulnerable theme version is in use.

To detect the vulnerability on your system, you can check the installed version of the Archicon Theme in your WordPress installation.

  • Use WP-CLI command to check the theme version: wp theme list --status=active
  • Manually check the theme version in the WordPress admin dashboard under Appearance > Themes.

There are no specific network commands or signatures provided to detect exploitation attempts, but monitoring for unusual PHP Object Injection patterns or suspicious requests targeting the theme files may help.

Mitigation Strategies

The primary and recommended mitigation step is to update the Archicon Theme to version 1.7 or later, where the vulnerability has been patched.

Until the update can be applied, you can use Patchstack's mitigation rules which can automatically block exploitation attempts, providing immediate protection.

Additionally, seeking assistance from your hosting provider or web developers to implement temporary protections or monitoring is advised.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-32506. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart