Unauthenticated PHP Object Injection in Laurits Theme by Patchstack
CVE-2026-40736
8.1HIGH
What is CVE-2026-40736?
The Laurits Theme for WordPress, specifically versions up to 1.5.1, is susceptible to an unauthenticated PHP Object Injection vulnerability. This risk can allow attackers to exploit untrusted data being injected into PHP objects, potentially leading to unauthorized code execution or data manipulation. Site owners should promptly upgrade to secure versions to mitigate these risks.
Affected Version(s)
Laurits <= 1.5.1