Unauthenticated PHP Object Injection in Kapee Theme Versions
CVE-2026-39446

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-39446?

The Kapee theme for WordPress is susceptible to a vulnerability that allows unauthenticated users to inject PHP objects. This issue affects versions of Kapee below 1.7.0, posing a risk of arbitrary code execution. Attackers can exploit this flaw to compromise site integrity and perform unauthorized actions, highlighting the imperative for users to update to the patched version to ensure their site's security.

Affected Version(s)

Kapee < 1.7.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.