Unauthenticated PHP Object Injection in Agora Theme by Patchstack
CVE-2026-65578
9.8CRITICAL
What is CVE-2026-65578?
The Agora Theme for WordPress, in its versions up to 1.9, is susceptible to an unauthenticated PHP object injection vulnerability. This security flaw allows attackers to inject malicious objects into the application, potentially leading to arbitrary code execution and unauthorized access to sensitive data. It is crucial for users of the affected versions to apply security patches and updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Agora <= 1.9