Unauthenticated PHP Object Injection Vulnerability in Léonie Theme by WordPress
CVE-2026-40758
8.1HIGH
What is CVE-2026-40758?
The Léonie WordPress theme, specifically in versions up to 1.2.1, is susceptible to an unauthenticated PHP Object Injection vulnerability. This flaw allows unauthorized users to exploit the theme, potentially leading to arbitrary code execution and compromising the integrity of the website. It is essential for users of the Léonie theme to apply all patches and updates to secure their WordPress installations against this threat.
Affected Version(s)
Léonie <= 1.2.1