Unauthenticated PHP Object Injection in Micdrop Theme by Patchstack
CVE-2026-39580
8.1HIGH
What is CVE-2026-39580?
The Micdrop theme for WordPress, specifically versions up to 1.3.1, is susceptible to an unauthenticated PHP Object Injection flaw. This vulnerability allows attackers to exploit certain functions without authentication, potentially leading to the execution of arbitrary code or manipulation of the web application. It is crucial for website owners using Micdrop to apply the latest updates to safeguard their data and ensure the integrity of their online presence.
Affected Version(s)
Micdrop <= 1.3.1