Unauthenticated PHP Object Injection in Manufaktur Solutions by Manufaktur
CVE-2026-40752

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-40752?

This vulnerability allows unauthenticated users to exploit a PHP Object Injection issue in the Manufaktur Solutions theme, potentially leading to the execution of arbitrary code and compromising website security. Proper input validation and sanitization measures can mitigate this type of vulnerability. Site owners using Manufaktur Solutions should consider upgrading to a secure version to protect against unauthorized access and exploits.

Affected Version(s)

Manufaktur Solutions <= 1.1.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson | Patchstack Bug Bounty Program
.