Unauthenticated PHP Object Injection in Equadio by Patchstack
CVE-2026-62087
9.8CRITICAL
What is CVE-2026-62087?
An unauthenticated PHP object injection vulnerability exists in the Equadio theme for WordPress, allowing attackers to manipulate object instances and potentially execute arbitrary code. This flaw affects all versions of Equadio up to 1.1.4, posing a significant threat to websites utilizing this theme. Users are urged to update their installations promptly to mitigate potential security risks.
Affected Version(s)
Equadio <= 1.1.4