Unauthenticated PHP Object Injection in Kapee Theme Versions
CVE-2026-39446
8.1HIGH
What is CVE-2026-39446?
The Kapee theme for WordPress is susceptible to a vulnerability that allows unauthenticated users to inject PHP objects. This issue affects versions of Kapee below 1.7.0, posing a risk of arbitrary code execution. Attackers can exploit this flaw to compromise site integrity and perform unauthorized actions, highlighting the imperative for users to update to the patched version to ensure their site's security.
Affected Version(s)
Kapee < 1.7.0