CVE-2026-94064
Received Received - Intake

Deserialization of Untrusted Data in Neo | Barber Shop WordPress Theme

Vulnerability report for CVE-2026-94064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Patchstack

Description

Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
BuddhaThemes Neo | Barber Shop WordPress Theme 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Deserialization of Untrusted Data vulnerability in the BuddhaThemes Neo | Barber Shop WordPress Theme (versions up to 3.5). It allows Object Injection, which could let attackers execute malicious code or manipulate data by exploiting improper handling of serialized objects.

Detection Guidance

Detecting this vulnerability requires checking if the Neo | Barber Shop WordPress Theme version 3.5 or below is installed. Inspect WordPress installations for the theme and verify its version. No specific commands are provided in the context, but monitoring for unusual server behavior or unauthorized actions may indicate exploitation.

Impact Analysis

If exploited, this vulnerability could allow attackers to take control of your WordPress site, steal sensitive data, or inject malicious content. It may also enable unauthorized access to user accounts or site administration.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR (data protection) and HIPAA (health data privacy). Non-compliance may result in legal penalties, fines, or reputational damage due to unauthorized data exposure.

Mitigation Strategies

Update the Neo | Barber Shop WordPress Theme to the latest version to address the deserialization flaw. If an update is unavailable, consider disabling or removing the theme immediately. Monitor for suspicious activity and review access logs for unauthorized actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94064. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart