Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Car Zone WordPress Theme Allows Hackers to Inject Malicious Code

CVE-2026-27338
Summary

A security issue in Car Zone, a WordPress theme used for car dealerships, allows hackers to inject malicious code. This can lead to unauthorized access to sensitive data or the entire website being taken over. Update to version 4.0 or later to fix this issue.

Original title
Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7.
Original description
Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7.
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026