Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Update the WordPress Roisin Theme to the latest available version (at least 1.5).