Unauthenticated PHP Object Injection in Avala <= 1.1.4 versions.CreditsJoão Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty ProgramReferenceshttps://patchstack.com/database/wordpress/theme/avala/vulnerability/wordpress-avala-theme-1-1-4-php-object-injection-vulnerability?_s_id=cve