PHP Object Injection Vulnerability in ShiftUp Theme by PatchStack
CVE-2026-40733
8.1HIGH
What is CVE-2026-40733?
The ShiftUp theme versions up to 1.3 are vulnerable to an unauthenticated PHP object injection, allowing attackers to exploit the vulnerability without any user authentication. This can lead to potential unauthorized access or manipulation of sensitive data within the WordPress environment, compromising the security and integrity of the affected applications.
Affected Version(s)
ShiftUp <= 1.3